Defender Activity Monitoring for Vessel Fleets

Cyber Detective now gives shore teams a clearer way to review Microsoft Defender health, detections, and follow-up signals across vessel PCs.

Microsoft Defender can tell you a lot.

But only if the information reaches the people who need to act on it.

On vessels, that is not always straightforward. PCs may report late. Some systems are offline for long periods. Bandwidth is limited. Different vessels may return audit data at different times.

Cyber Detective is designed for that reality.

The Defender Activity view brings Defender health and detection data into the portal so shore teams can review vessel PCs without digging through raw audit output.

Cyber Detective virus correlation overview showing Defender detections grouped by likely source across vessel PCs
The virus correlation overview groups Defender detections by likely origin, affected PCs, affected vessels, top source, and latest detection time.

What is in the monitoring view

The Defender monitoring view is designed to answer both health and activity questions.

It can show:

  • total Defender detections returned by recent audit data
  • affected PCs and affected vessels
  • Defender real-time protection state
  • tamper protection state
  • anti-malware and anti-spyware signature versions
  • signature age and last update time
  • scan age for quick and full scans
  • reboot requirement after Defender activity
  • engine and security intelligence versions
  • recent threat names and affected computers
  • longer-running virus alert history from VIRUSFOUND records
  • cross-correlation between threats, vessels, PCs, source types, paths, and processes

This is deliberately practical. The screen is not trying to be a full SIEM. It is trying to give the shore team enough Defender context to decide what to inspect next.


What the Defender view helps answer

The useful questions are usually simple:

  • is Defender running?
  • are signatures current?
  • which PCs have had detections?
  • which vessels are affected?
  • are detections coming from disk, browser downloads, network shares, or removable media?
  • is this a one-off event or a repeated pattern?

Cyber Detective combines these signals into a fleet view.

That matters because a vessel security event is rarely just a single line in an antivirus log. The follow-up often depends on context: where the file was seen, which PC was involved, whether similar events happened elsewhere, and whether the endpoint is still reporting healthy protection status.


From raw Defender output to a usable report

Defender events can include useful details such as threat name, threat ID, severity, category, path, detection origin, detection type, detection source, user, process name, security intelligence version, and engine version.

Cyber Detective extracts those fields where available and presents them as fleet-level report data.

That means the operator can review the same event at different levels:

  • fleet summary
  • source category
  • top threat name
  • affected vessel
  • affected PC
  • raw event details when needed

The raw data remains useful, but it no longer has to be the first place the team starts.


Built around audit data

The report is based on Defender data returned through vessel audits.

That makes it useful for maritime environments where continuous cloud access cannot be assumed. Instead of depending only on a live endpoint session, the portal can present the latest collected facts and make them easier to review.

The goal is not to replace Microsoft Defender.

The goal is to make Defender's output more operational for vessel IT teams.


Why this matters

Security teams do not need more noise.

They need a fast way to see which systems need attention.

By grouping Defender detections across vessel PCs, Cyber Detective helps teams move from "Defender saw something somewhere" to a more useful question:

Which vessel, which PC, what source, and has this happened before?

That is the difference between an alert and a usable fleet security view.

Interactive demo

Try USB Manager Local Edition in the browser.

Walk through USB blocking, temporary unblock, Secure Copy, ECDIS media, Defender update USB creation, settings, license, and updates.