{"id":30646,"date":"2025-12-29T09:32:53","date_gmt":"2025-12-29T09:32:53","guid":{"rendered":"https:\/\/endusersupports.com\/?p=30646"},"modified":"2025-12-30T10:54:03","modified_gmt":"2025-12-30T10:54:03","slug":"self-healing-automation-to-update-the-virus-definition","status":"publish","type":"post","link":"https:\/\/endusersupports.com\/index.php\/2025\/12\/29\/self-healing-automation-to-update-the-virus-definition\/","title":{"rendered":"Self-healing Automation to update the Virus Definition"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30646\" class=\"elementor elementor-30646\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-abc6168 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"abc6168\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-bdf8fa7\" data-id=\"bdf8fa7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ca7f9bb elementor-widget elementor-widget-text-editor\" data-id=\"ca7f9bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"color: #ffffff;\"><b>Update the Virus Definition<\/b><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-90f2109 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"90f2109\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9e956b1\" data-id=\"9e956b1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-116b2f0 elementor-widget elementor-widget-text-editor\" data-id=\"116b2f0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Follow the below steps to make ready your Self-Healing environment.\u00a0<\/p><ol><li>Download the\u00a0<strong>Detection <\/strong>and <strong>Remediation PowerShell\u00a0<\/strong>script from my GitHub account. <a href=\"https:\/\/github.com\/harvansh007\/Defender-Self-Healing-Automation---Virus-Definition-Update\">https:\/\/github.com\/harvansh007\/Defender-Self-Healing-Automation&#8212;Virus-Definition-Update<\/a><\/li><li>Create a Group in Intune that will used to deploy the Remediation script.<\/li><li>Create the Self remediation script.\u00a0<\/li><\/ol><p>Login to Intune console and click on <strong>Devices\u00a0<\/strong>then click on\u00a0<strong>Script and Remediation&#8217;s.\u00a0<\/strong>Click on Create under Remediation section.<\/p><p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-full wp-image-30647 aligncenter\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-1.png\" alt=\"\" width=\"1350\" height=\"506\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-1.png 1350w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-1-300x112.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-1-1024x384.png 1024w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-1-768x288.png 768w\" sizes=\"(max-width: 1350px) 100vw, 1350px\" \/><\/p><p>Fill the Name details and click on Next.<\/p><p><img decoding=\"async\" class=\"aligncenter size-full wp-image-30648\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-2.png\" alt=\"\" width=\"918\" height=\"645\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-2.png 918w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-2-300x211.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-2-768x540.png 768w\" sizes=\"(max-width: 918px) 100vw, 918px\" \/><\/p><p>Now Select the Detection and Remediation script and click on next.<\/p><p><img decoding=\"async\" class=\"aligncenter size-full wp-image-30649\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-3.png\" alt=\"\" width=\"822\" height=\"641\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-3.png 822w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-3-300x234.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-3-768x599.png 768w\" sizes=\"(max-width: 822px) 100vw, 822px\" \/><\/p><p>Use the Default Scope and click on Next.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30650\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-4.png\" alt=\"\" width=\"803\" height=\"371\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-4.png 803w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-4-300x139.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-4-768x355.png 768w\" sizes=\"(max-width: 803px) 100vw, 803px\" \/><\/p><p>Add the Group with we created for Remediation.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30651\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-5.png\" alt=\"\" width=\"795\" height=\"639\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-5.png 795w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-5-300x241.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-5-768x617.png 768w\" sizes=\"(max-width: 795px) 100vw, 795px\" \/><\/p><p>Now everything is ready and click on Create.<\/p><p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-30652\" src=\"http:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-6.png\" alt=\"\" width=\"870\" height=\"637\" srcset=\"https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-6.png 870w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-6-300x220.png 300w, https:\/\/endusersupports.com\/wp-content\/uploads\/2025\/12\/Self-Healing-Automation-to-Update-the-Virus-Definition-6-768x562.png 768w\" sizes=\"(max-width: 870px) 100vw, 870px\" \/><\/p><p>Now your Self-Healing script is ready.\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fc02bd1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fc02bd1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5a4c9ad\" data-id=\"5a4c9ad\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-86d8584 elementor-widget elementor-widget-text-editor\" data-id=\"86d8584\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Use the below KQL query to get all non-updated device more than 5 days.<\/p><p><strong><em>DeviceTvmSecureConfigurationAssessment<\/em><\/strong><\/p><div><div><strong><em>| where Timestamp &gt; ago(30d)<\/em><\/strong><\/div><div><strong><em>| where \u00a0ConfigurationId == &#8216;scid-2011&#8242; and Context !='[]&#8217;<\/em><\/strong><\/div><div><strong><em>| extend SigUpdate = todatetime(parse_json(Context)[0][2])<\/em><\/strong><\/div><div><strong><em>| extend SigAge = datetime_diff(&#8216;day&#8217;,now(),SigUpdate)<\/em><\/strong><\/div><div><strong><em>| where SigAge &gt; 5<\/em><\/strong><\/div><div><strong><em>| project Timestamp, DeviceName, SigAge, SigUpdate<\/em><\/strong><\/div><div>\u00a0<\/div><\/div><p>Add these devices in the group.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Update the Virus Definition Follow the below steps to make ready your Self-Healing environment.\u00a0 Download the\u00a0Detection and Remediation PowerShell\u00a0script from my GitHub account. https:\/\/github.com\/harvansh007\/Defender-Self-Healing-Automation&#8212;Virus-Definition-Update Create a Group in Intune that will used to deploy the Remediation script. Create the Self remediation script.\u00a0 Login to Intune console and click on Devices\u00a0then click on\u00a0Script and Remediation&#8217;s.\u00a0Click on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":30657,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[19,14],"tags":[],"class_list":["post-30646","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-defender-for-endpoint","category-mem"],"views":102,"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/comments?post=30646"}],"version-history":[{"count":9,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30646\/revisions"}],"predecessor-version":[{"id":30666,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/posts\/30646\/revisions\/30666"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/media\/30657"}],"wp:attachment":[{"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/media?parent=30646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/categories?post=30646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/endusersupports.com\/index.php\/wp-json\/wp\/v2\/tags?post=30646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}