Configuration

MultCheck relies on a configuration file to define the rules for the checks. The configuration file is a JSON file that contains the following fields:

  • cmd: The command to be executed to run the AV scanner.
  • out: The output format of a positive detection.

An example configuration file is shown below:

{
  "cmd": "& 'C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.24050.7-0\\MpCmdRun.exe' -Scan -ScanType 3 -File '{{file}}' -DisableRemediation -Trace -Level 0x10",
  "out": "Threat information"
}
ℹ️
The cmd field is a string that contains the command to run the AV scanner. The {{file}} placeholder is used to specify the file to be scanned. The placeholder is replaced with the actual file path during runtime.
⚠️
Before running MultCheck, ensure that the AV scanner is installed on the system and the path to the AV scanner is correctly specified in the configuration file. A good practice is to test the AV scanner command beforehand to ensure that it is working as expected.