You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过C# .NET程序获取Windows 11 Defender安全警报并以JSON形式发送至LimaCharlie Webhook

如何通过C# .NET程序获取Windows 11 Defender安全警报并以JSON形式发送至LimaCharlie Webhook

嘿,我来帮你搞定这个问题!你目前遇到两个核心问题:一是PowerShell命令的参数位置错了,二是找错了Windows Defender日志的来源,咱们一步步来修正。

先说说你出错的原因

你收到的Where-Object : A parameter cannot be found that matches parameter name 'MaxEvents'错误,是因为-MaxEvents是Get-WinEvent的专属参数,不是Where-Object的,你把它放在过滤语句后面就会触发这个报错。另外,Windows Defender的安全警报并不在Application日志里,也不是Microsoft-Windows-Security-Auditing(这个是系统的安全审计日志),Defender的日志存在专门的Microsoft-Windows-Windows Defender/Operational日志集里。

修正后的PowerShell命令

正确获取最近10条Defender日志的PowerShell命令如下:

Get-WinEvent -LogName "Microsoft-Windows-Windows Defender/Operational" -MaxEvents 10 | Where-Object {$_.ProviderName -eq 'Microsoft-Windows-Windows Defender'} | ConvertTo-Json -Depth 3
  • -LogName指定了Defender专属的日志集
  • -MaxEvents放在Get-WinEvent后面,属于正确的参数位置
  • 额外加Where-Object过滤Provider,确保只拿到Defender的日志(其实指定日志集后可以不用,但加上更保险)

修正你的C#代码

接下来把Program.cs里的相关代码更新,同时优化逻辑(比如只有JSON解析成功才发送请求,避免无效提交):

using System;
using System.Diagnostics;
using System.Net.Http;
using System.Text;
using System.Threading.Tasks;
using Newtonsoft.Json;

class Program
{
    static async Task Main(string[] args)
    {
        // Load configuration or prompt user for details
        Config config = ConfigManager.LoadConfig() ?? ConfigManager.PromptUserForConfig();

        // 改为发送Defender日志
        await SendDefenderLogs(config);
    }

    /// <summary>
    /// Fetches the last 10 Windows Defender Event logs and sends them to LimaCharlie.
    /// </summary>
    static async Task SendDefenderLogs(Config config)
    {
        try
        {
            // 修正后的PowerShell命令
            ProcessStartInfo psi = new ProcessStartInfo
            {
                FileName = "powershell",
                Arguments = "-Command \"Get-WinEvent -LogName 'Microsoft-Windows-Windows Defender/Operational' -MaxEvents 10 | Where-Object {$_.ProviderName -eq 'Microsoft-Windows-Windows Defender'} | ConvertTo-Json -Depth 3\"",
                RedirectStandardOutput = true,
                UseShellExecute = false,
                CreateNoWindow = true
            };

            using (Process process = new Process { StartInfo = psi })
            {
                process.Start();
                string output = process.StandardOutput.ReadToEnd();
                process.WaitForExit();

                // 先验证输出是否为空
                if (string.IsNullOrWhiteSpace(output))
                {
                    Console.WriteLine("Program·SendDefenderLogs()·ERROR: No logs retrieved.");
                    return;
                }

                object jsonObject = null;
                try
                {
                    jsonObject = JsonConvert.DeserializeObject(output);
                    Console.WriteLine("Program·SendDefenderLogs()·Successfully retrieved valid Defender logs.");
                }
                catch (JsonException ex)
                {
                    Console.WriteLine("Program·SendDefenderLogs()·ERROR: The output is not valid JSON. Here is the plain text output:");
                    Console.WriteLine(output);
                    Console.WriteLine($"JSON Error Details: {ex.Message}");
                    return; // JSON无效,终止发送流程
                }

                // 只有JSON有效才发送到LimaCharlie
                using (HttpClient client = new HttpClient())
                {
                    client.DefaultRequestHeaders.Add("lc-secret", config.WebhookSecret);
                    HttpContent content = new StringContent(output, Encoding.UTF8, "application/json");

                    // 处理HookURL格式
                    string hookURL = config.HookURL.Contains(".hook.limacharlie.io") 
                        ? config.HookURL 
                        : $"{config.HookURL}.hook.limacharlie.io";
                    string webhookUrl = $"https://{hookURL}/{config.OrgId}/{config.WebhookName}";

                    HttpResponseMessage response = await client.PostAsync(webhookUrl, content);

                    if (response.IsSuccessStatusCode)
                    {
                        Console.WriteLine($"Program·SendDefenderLogs()·Logs successfully sent to LimaCharlie. Status: {response.StatusCode}");
                    }
                    else
                    {
                        Console.WriteLine($"Program·SendDefenderLogs()·ERROR: Failed to send logs. Status: {response.StatusCode} - {response.ReasonPhrase}");
                    }
                }
            }
        }
        catch (Exception ex)
        {
            Console.WriteLine($"Program·SendDefenderLogs()·ERROR: {ex.Message}");
            Console.WriteLine($"Stack Trace: {ex.StackTrace}");
        }
    }
}

其他文件说明

你的Config.cs和ConfigManager.cs文件不需要做任何修改,它们的配置逻辑是正常的。

额外提示

  • 确保你的程序以管理员权限运行,因为读取Windows Defender的Operational日志需要较高权限,否则可能会遇到访问被拒绝的错误。
  • 如果需要获取更多日志,只需要调整-MaxEvents后面的数字即可。

备注:内容来源于stack exchange,提问作者Europa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.15 03:34:40