Pull the verdicts you already have.
- What happensAftermath reads Windows Defender's own detection history and event logs on launch.
- What it's looking atDefender's threat log, Windows Event Viewer entries, and scan history — nothing Aftermath scans itself.
- What the technician seesOverview: how many threats were found, how many are quarantined, when the last scan ran.
- OutputA starting picture of what's already been caught, before any manual digging begins.