如何通过C# .NET程序获取Windows 11 Defender安全警报并以JSON形式发送至LimaCharlie Webhook
如何通过C# .NET程序获取Windows 11 Defender安全警报并以JSON形式发送至LimaCharlie Webhook
嘿,我来帮你搞定这个问题!你目前遇到两个核心问题:一是PowerShell命令的参数位置错了,二是找错了Windows Defender日志的来源,咱们一步步来修正。
先说说你出错的原因
你收到的Where-Object : A parameter cannot be found that matches parameter name 'MaxEvents'错误,是因为-MaxEvents是Get-WinEvent的专属参数,不是Where-Object的,你把它放在过滤语句后面就会触发这个报错。另外,Windows Defender的安全警报并不在Application日志里,也不是Microsoft-Windows-Security-Auditing(这个是系统的安全审计日志),Defender的日志存在专门的Microsoft-Windows-Windows Defender/Operational日志集里。
修正后的PowerShell命令
正确获取最近10条Defender日志的PowerShell命令如下:
Get-WinEvent -LogName "Microsoft-Windows-Windows Defender/Operational" -MaxEvents 10 | Where-Object {$_.ProviderName -eq 'Microsoft-Windows-Windows Defender'} | ConvertTo-Json -Depth 3
-LogName指定了Defender专属的日志集-MaxEvents放在Get-WinEvent后面,属于正确的参数位置- 额外加
Where-Object过滤Provider,确保只拿到Defender的日志(其实指定日志集后可以不用,但加上更保险)
修正你的C#代码
接下来把Program.cs里的相关代码更新,同时优化逻辑(比如只有JSON解析成功才发送请求,避免无效提交):
using System; using System.Diagnostics; using System.Net.Http; using System.Text; using System.Threading.Tasks; using Newtonsoft.Json; class Program { static async Task Main(string[] args) { // Load configuration or prompt user for details Config config = ConfigManager.LoadConfig() ?? ConfigManager.PromptUserForConfig(); // 改为发送Defender日志 await SendDefenderLogs(config); } /// <summary> /// Fetches the last 10 Windows Defender Event logs and sends them to LimaCharlie. /// </summary> static async Task SendDefenderLogs(Config config) { try { // 修正后的PowerShell命令 ProcessStartInfo psi = new ProcessStartInfo { FileName = "powershell", Arguments = "-Command \"Get-WinEvent -LogName 'Microsoft-Windows-Windows Defender/Operational' -MaxEvents 10 | Where-Object {$_.ProviderName -eq 'Microsoft-Windows-Windows Defender'} | ConvertTo-Json -Depth 3\"", RedirectStandardOutput = true, UseShellExecute = false, CreateNoWindow = true }; using (Process process = new Process { StartInfo = psi }) { process.Start(); string output = process.StandardOutput.ReadToEnd(); process.WaitForExit(); // 先验证输出是否为空 if (string.IsNullOrWhiteSpace(output)) { Console.WriteLine("Program·SendDefenderLogs()·ERROR: No logs retrieved."); return; } object jsonObject = null; try { jsonObject = JsonConvert.DeserializeObject(output); Console.WriteLine("Program·SendDefenderLogs()·Successfully retrieved valid Defender logs."); } catch (JsonException ex) { Console.WriteLine("Program·SendDefenderLogs()·ERROR: The output is not valid JSON. Here is the plain text output:"); Console.WriteLine(output); Console.WriteLine($"JSON Error Details: {ex.Message}"); return; // JSON无效,终止发送流程 } // 只有JSON有效才发送到LimaCharlie using (HttpClient client = new HttpClient()) { client.DefaultRequestHeaders.Add("lc-secret", config.WebhookSecret); HttpContent content = new StringContent(output, Encoding.UTF8, "application/json"); // 处理HookURL格式 string hookURL = config.HookURL.Contains(".hook.limacharlie.io") ? config.HookURL : $"{config.HookURL}.hook.limacharlie.io"; string webhookUrl = $"https://{hookURL}/{config.OrgId}/{config.WebhookName}"; HttpResponseMessage response = await client.PostAsync(webhookUrl, content); if (response.IsSuccessStatusCode) { Console.WriteLine($"Program·SendDefenderLogs()·Logs successfully sent to LimaCharlie. Status: {response.StatusCode}"); } else { Console.WriteLine($"Program·SendDefenderLogs()·ERROR: Failed to send logs. Status: {response.StatusCode} - {response.ReasonPhrase}"); } } } } catch (Exception ex) { Console.WriteLine($"Program·SendDefenderLogs()·ERROR: {ex.Message}"); Console.WriteLine($"Stack Trace: {ex.StackTrace}"); } } }
其他文件说明
你的Config.cs和ConfigManager.cs文件不需要做任何修改,它们的配置逻辑是正常的。
额外提示
- 确保你的程序以管理员权限运行,因为读取Windows Defender的Operational日志需要较高权限,否则可能会遇到访问被拒绝的错误。
- 如果需要获取更多日志,只需要调整
-MaxEvents后面的数字即可。
备注:内容来源于stack exchange,提问作者Europa
相关产品推荐
相关产品推荐

