@prefix schema: <https://schema.org/> .
@prefix skos: <http://www.w3.org/2004/02/skos/core#> .
@prefix rdf: <http://www.w3.org/1999/02/22-rdf-syntax-ns#> .
@prefix ks: <https://comcomponent.com/vocab/> .

<https://comcomponent.com/blog/windows-defender-false-positive-guide/#article>
    schema:about <https://comcomponent.com/knowledge/windows-defender-antivirus/>, <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:mentions <https://comcomponent.com/knowledge/cloud-protection/>, <https://comcomponent.com/knowledge/ml-based-detection/>, <https://comcomponent.com/knowledge/sample-submission-portal/>, <https://comcomponent.com/knowledge/mpcmdrun/>, <https://comcomponent.com/knowledge/quarantine/>, <https://comcomponent.com/knowledge/quarantine-restore/>, <https://comcomponent.com/knowledge/performance-analyzer/>, <https://comcomponent.com/knowledge/dev-drive/>, <https://comcomponent.com/knowledge/msmpeng/>, <https://comcomponent.com/knowledge/pua-classification/>, <https://comcomponent.com/knowledge/unknown-software-category/>, <https://comcomponent.com/knowledge/code-signing-cert/>, <https://comcomponent.com/knowledge/get-winevent/>, <https://comcomponent.com/knowledge/defender-for-endpoint/>, <https://comcomponent.com/knowledge/caro-naming/>, <https://comcomponent.com/knowledge/defender-performance-mode/>, <https://comcomponent.com/knowledge/cpu-throttling-setting/>, <https://comcomponent.com/knowledge/obfuscation/>, <https://comcomponent.com/knowledge/antivirus-minifilter/>, <https://comcomponent.com/knowledge/scan-performance-cost/>, <https://comcomponent.com/knowledge/reduced-protection/>, <https://comcomponent.com/knowledge/exclusion-setting/>, <https://comcomponent.com/knowledge/event-1116-1117/> .

<https://comcomponent.com/knowledge/windows-defender-antivirus/> a skos:Concept ;
    skos:prefLabel "Microsoft Defender ウイルス対策"@ja ;
    skos:definition "Windowsに組み込まれたウイルス対策ソフトで、機械学習・ふるまい分析・クラウド保護を組み合わせて脅威を判定する。"@ja ;
    skos:altLabel "Windows Defender" ;
    skos:altLabel "Microsoft Defender Antivirus" ;
    ks:uses <https://comcomponent.com/knowledge/ml-based-detection/> ;
    ks:uses <https://comcomponent.com/knowledge/cloud-protection/> ;
    ks:uses <https://comcomponent.com/knowledge/pua-classification/> ;
    ks:configuredBy <https://comcomponent.com/knowledge/mpcmdrun/> ;
    ks:uses <https://comcomponent.com/knowledge/msmpeng/> .

<https://comcomponent.com/knowledge/false-positive-detection/> a skos:Concept ;
    skos:prefLabel "誤検知(false positive)"@ja ;
    skos:definition "正規の無害なファイルが、ウイルス対策ソフトによって悪性と誤って判定されること。"@ja ;
    skos:altLabel "誤検知報告"@ja ;
    skos:altLabel "False Positive" .

<https://comcomponent.com/knowledge/ml-based-detection/> a skos:Concept ;
    skos:prefLabel "機械学習ベースの検知モデル"@ja ;
    skos:definition "既知の悪性パターンとの一致だけでなく、機械学習・応用科学・AIで「怪しさ」を推定する検知方式。2015年に静的シグネチャベースのエンジンから移行した。"@ja ;
    skos:altLabel "予測型モデル"@ja ;
    skos:altLabel "Predictive Protection" .

<https://comcomponent.com/knowledge/cloud-protection/> a skos:Concept ;
    skos:prefLabel "クラウド保護"@ja ;
    skos:definition "端末上で判定しきれないファイルのメタデータをクラウド保護サービスへ送り、スキャン・デトネーション・ビッグデータ分析で判定する仕組み。"@ja ;
    skos:altLabel "Cloud Protection" ;
    skos:altLabel "MAPS" .

<https://comcomponent.com/knowledge/unknown-software-category/> a skos:Concept ;
    skos:prefLabel "Unknown(認識されないソフトウェア)カテゴリ"@ja ;
    skos:definition "実績・ダウンロード数が少なく検出も未確立なソフトウェアの分類で、まだ検出されていないマルウェアの早期警戒システムと位置付けられる。"@ja ;
    skos:altLabel "Unknown Software" .

<https://comcomponent.com/knowledge/obfuscation/> a skos:Concept ;
    skos:prefLabel "難読化(オブファスケーション)"@ja ;
    skos:definition "クラス名・メソッド名を無意味な文字列に置き換えるなどして、逆コンパイル結果を読みにくくする加工。"@ja ;
    skos:altLabel "Obfuscation" .

<https://comcomponent.com/knowledge/pua-classification/> a skos:Concept ;
    skos:prefLabel "望ましくないアプリケーション(PUA)分類"@ja ;
    skos:definition "検出回避を狙うソフトや同梱インストーラーなど、ウイルスではないが望ましくない挙動を持つソフトウェアをMicrosoftが分類するカテゴリ。"@ja ;
    skos:altLabel "Potentially Unwanted Application" ;
    skos:altLabel "PUA" .

<https://comcomponent.com/knowledge/code-signing-cert/> a skos:Concept ;
    skos:prefLabel "コード署名証明書"@ja ;
    skos:definition "ソフトウェアの発行元を証明し、改ざんを検出するための証明書。"@ja ;
    skos:altLabel "Authenticode証明書"@ja ;
    ks:mitigates <https://comcomponent.com/knowledge/false-positive-detection/> .

<https://comcomponent.com/knowledge/mpcmdrun/> a skos:Concept ;
    skos:prefLabel "MpCmdRun.exe"@ja ;
    skos:definition "カスタムスキャン、隔離ファイルの復元、除外の検証などをコマンドラインから行えるMicrosoft Defenderの管理ツール。"@ja ;
    skos:altLabel "MpCmdRun" ;
    ks:uses <https://comcomponent.com/knowledge/quarantine-restore/> .

<https://comcomponent.com/knowledge/sample-submission-portal/> a skos:Concept ;
    skos:prefLabel "サンプル申請ポータル"@ja ;
    skos:definition "Microsoft Security Intelligenceが提供する、誤検知や未知のファイルを開発者として提出し判定を追跡できるオンライン申請窓口。"@ja ;
    skos:altLabel "Microsoft Security Intelligence submission" ;
    skos:altLabel "wdsi/filesubmission" ;
    ks:recommendedFor <https://comcomponent.com/knowledge/false-positive-detection/> .

<https://comcomponent.com/knowledge/quarantine/> a skos:Concept ;
    skos:prefLabel "隔離(quarantine)"@ja ;
    skos:definition "Defenderが脅威と判定したファイルを実行不能な状態で退避させる処置。"@ja ;
    skos:altLabel "検疫"@ja .

<https://comcomponent.com/knowledge/quarantine-restore/> a skos:Concept ;
    skos:prefLabel "隔離からの復元"@ja ;
    skos:definition "誤検知と確認できたファイルを、保護の履歴またはMpCmdRun.exe -Restoreで元の場所へ戻す操作。"@ja ;
    skos:altLabel "Restore Quarantined Files" .

<https://comcomponent.com/knowledge/event-1116-1117/> a skos:Concept ;
    skos:prefLabel "検知/処置イベント(ID 1116/1117)"@ja ;
    skos:definition "Defenderのイベントログに記録される、マルウェアまたは望ましくないソフトウェアの検出(1116)と、隔離などの処置(1117)を示すイベントID。"@ja ;
    skos:altLabel "イベントID 1116"@ja ;
    skos:altLabel "イベントID 1117"@ja ;
    ks:verifiedBy <https://comcomponent.com/knowledge/get-winevent/> ;
    ks:uses <https://comcomponent.com/knowledge/caro-naming/> .

<https://comcomponent.com/knowledge/get-winevent/> a skos:Concept ;
    skos:prefLabel "Get-WinEvent"@ja ;
    skos:definition "イベントログをフィルターして取得するPowerShellコマンドレット。FilterHashtableでの絞り込みに対応し、NTLM監査ログなど大量のイベントの集計に使う。"@ja .

<https://comcomponent.com/knowledge/caro-naming/> a skos:Concept ;
    skos:prefLabel "CARO命名規則"@ja ;
    skos:definition "ウイルス対策研究者団体CAROが定めた、型/プラットフォーム/ファミリ名という構造でマルウェアを命名する業界標準の規則。"@ja ;
    skos:altLabel "Computer Antivirus Research Organization" ;
    skos:altLabel "マルウェア命名規則"@ja .

<https://comcomponent.com/knowledge/exclusion-setting/> a skos:Concept ;
    skos:prefLabel "除外設定(フォルダー除外)"@ja ;
    skos:definition "指定したパス・プロセスをウイルス対策のスキャン対象から外す設定。効くのはその設定を持つ製品自身のフィルターだけで、保護レベルを下げるトレードオフを伴う。"@ja ;
    skos:altLabel "フォルダー除外"@ja ;
    skos:altLabel "スキャン除外"@ja ;
    ks:mayCause <https://comcomponent.com/knowledge/reduced-protection/> .

<https://comcomponent.com/knowledge/reduced-protection/> a skos:Concept ;
    skos:prefLabel "保護レベルの低下"@ja ;
    skos:definition "除外設定などによってスキャン対象から外れた結果、その範囲の脅威検出・防御が働かなくなること。"@ja .

<https://comcomponent.com/knowledge/defender-for-endpoint/> a skos:Concept ;
    skos:prefLabel "Microsoft Defender for Endpoint(EDR)"@ja ;
    skos:definition "組織向けのエンドポイント検知・対応(EDR)製品で、除外を設定したファイルでも独自のアラートや検知を発生させ得る。"@ja ;
    skos:altLabel "Defender for Endpoint" ;
    skos:altLabel "EDR" ;
    ks:mitigates <https://comcomponent.com/knowledge/false-positive-detection/> .

<https://comcomponent.com/knowledge/msmpeng/> a skos:Concept ;
    skos:prefLabel "MsMpEng.exe(Antimalware Service Executable)"@ja ;
    skos:definition "Microsoft Defenderウイルス対策のサービス本体で、リアルタイム保護の既定動作としてファイルを開いた時点で同期的にスキャンする。"@ja ;
    skos:altLabel "Antimalware Service Executable" ;
    ks:uses <https://comcomponent.com/knowledge/antivirus-minifilter/> .

<https://comcomponent.com/knowledge/antivirus-minifilter/> a skos:Concept ;
    skos:prefLabel "ウイルス対策ミニフィルター"@ja ;
    skos:definition "ファイルI/O中のウイルス検出・駆除を行うミニフィルター。FSFilter Anti-Virus帯(320000〜329999)に位置する。Microsoft DefenderのWdFilterなどが該当する。"@ja ;
    skos:altLabel "WdFilter" ;
    skos:altLabel "AVミニフィルター"@ja ;
    skos:broader <https://comcomponent.com/knowledge/minifilter/> .

<https://comcomponent.com/knowledge/scan-performance-cost/> a skos:Concept ;
    skos:prefLabel "スキャンによる性能コスト"@ja ;
    skos:definition "ウイルス対策ミニフィルターによるファイルスキャンがI/Oに追加する処理時間。大量の小ファイルを扱うワークロードで支配的になりやすい。"@ja ;
    skos:altLabel "スキャンコスト"@ja .

<https://comcomponent.com/knowledge/performance-analyzer/> a skos:Concept ;
    skos:prefLabel "Performance analyzer"@ja ;
    skos:definition "New-MpPerformanceRecordingでスキャンのパフォーマンス記録を採取し、Get-MpPerformanceReportで集計してスキャン負荷の中心を特定するDefenderの分析ツール。"@ja ;
    skos:altLabel "New-MpPerformanceRecording" ;
    skos:altLabel "Get-MpPerformanceReport" .

<https://comcomponent.com/knowledge/dev-drive/> a skos:Concept ;
    skos:prefLabel "Dev Drive"@ja ;
    skos:definition "開発ワークロード向けに設計された専用ボリューム。Microsoft Defenderがパフォーマンスモード(非同期スキャン)で動作し、フォルダー除外の安全な代替と位置付けられる。"@ja ;
    ks:uses <https://comcomponent.com/knowledge/defender-performance-mode/> ;
    ks:recommendedFor <https://comcomponent.com/knowledge/scan-performance-cost/> .

<https://comcomponent.com/knowledge/defender-performance-mode/> a skos:Concept ;
    skos:prefLabel "パフォーマンスモード(open now, scan later)"@ja ;
    skos:definition "ファイルオープン時に同期スキャンする既定動作の代わりに、オープン完了後へスキャンを遅延させる非同期方式。フォルダ除外より高い保護を保ったまま性能を改善する。"@ja ;
    skos:altLabel "Performance Mode" ;
    ks:mitigates <https://comcomponent.com/knowledge/scan-performance-cost/> .

<https://comcomponent.com/knowledge/cpu-throttling-setting/> a skos:Concept ;
    skos:prefLabel "スキャンのCPU使用率上限(-CpuThrottling/ScanAvgCPULoadFactor)"@ja ;
    skos:definition "オンデマンドスキャンのCPU使用率に、平均としてこの割合を超えないようにする目安上限を設定する仕組み。"@ja ;
    skos:altLabel "ScanAvgCPULoadFactor" ;
    skos:altLabel "-CpuThrottling" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/windows-defender-antivirus/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/ml-based-detection/> ;
    schema:description "Defenderは2015年に静的シグネチャベースのエンジンから、機械学習・応用科学・AIを使う予測型モデルへ移行した"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/microsoft-defender-antivirus-windows> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/windows-defender-antivirus/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/cloud-protection/> ;
    schema:description "端末だけで判定できないファイルはメタデータがクラウド保護サービスへ送られ、多くの場合ミリ秒単位で判定が返る"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/cloud-protection-microsoft-antivirus-sample-submission> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/unknown-software-category/> ;
    rdf:predicate ks:mayCause ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "実績のない未知のソフトウェアはUnknownカテゴリとして警告対象になりやすく、正規アプリでも誤検知される原因になり得る"@ja ;
    ks:evidence <https://learn.microsoft.com/unified-secops/criteria> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/obfuscation/> ;
    rdf:predicate ks:mayCause ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "コードと目的を隠す難読化や自己解凍・同梱パッケージングは、マルウェアが多用する構造と外形上区別がつきにくく誤検知されやすい"@ja ;
    ks:evidence <https://learn.microsoft.com/unified-secops/criteria> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/windows-defender-antivirus/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/pua-classification/> ;
    schema:description "Defenderはウイルスとは別に、検出回避を狙うソフトや同梱インストーラーを望ましくないアプリケーション(PUA)として分類する"@ja ;
    ks:evidence <https://learn.microsoft.com/unified-secops/criteria> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/code-signing-cert/> ;
    rdf:predicate ks:mitigates ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "信頼されたルート認証局の証明書で一貫して署名し続けると、調査チームが出所を素早く特定でき誤検知や既知リスト入りの遅れを軽減できる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-xdr/developer-faq> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/windows-defender-antivirus/> ;
    rdf:predicate ks:configuredBy ;
    rdf:object <https://comcomponent.com/knowledge/mpcmdrun/> ;
    schema:description "Defenderはコマンドラインツールmpcmdrun.exeでカスタムスキャン・隔離管理・除外検証など多くの操作を構成できる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/command-line-arguments-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/mpcmdrun/> ;
    rdf:predicate ks:mitigates ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "リリース前に自分のビルド成果物をMpCmdRun.exeでスキャンしておくと、検知の有無を出荷前に把握でき配布後の誤検知トラブルを減らせる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/command-line-arguments-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/sample-submission-portal/> ;
    rdf:predicate ks:recommendedFor ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "誤検知の恒久対応として、Microsoft Security Intelligenceのサンプル申請ポータルへ開発者として提出することが公式に案内されている"@ja ;
    ks:evidence <https://learn.microsoft.com/unified-secops/submission-guide> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/false-positive-detection/> ;
    rdf:predicate ks:mayCause ;
    rdf:object <https://comcomponent.com/knowledge/quarantine/> ;
    schema:description "誤検知によってファイルが隔離されることがある"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/restore-quarantined-files-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/mpcmdrun/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/quarantine-restore/> ;
    schema:description "MpCmdRun.exeの-Restoreオプションで、隔離されているファイルの一覧表示と元の場所への復元ができる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/restore-quarantined-files-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/event-1116-1117/> ;
    rdf:predicate ks:verifiedBy ;
    rdf:object <https://comcomponent.com/knowledge/get-winevent/> ;
    schema:description "Defenderの検知(1116)と処置(1117)のイベントはGet-WinEventの-FilterHashtableで絞り込んで確認できる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/troubleshoot-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/false-positive-detection/> ;
    rdf:predicate ks:verifiedBy ;
    rdf:object <https://comcomponent.com/knowledge/event-1116-1117/> ;
    schema:description "Windows Defenderでの誤検知では、事実確認は保護の履歴に加えてイベントID 1116/1117のログで検知名と対象ファイルを特定することから始める"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/troubleshoot-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/event-1116-1117/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/caro-naming/> ;
    schema:description "検知イベントに記録される脅威名は、CARO(Computer Antivirus Research Organization)のマルウェア命名規則に従う"@ja ;
    ks:evidence <https://learn.microsoft.com/unified-secops/malware-naming> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/exclusion-setting/> ;
    rdf:predicate ks:recommendedFor ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "誤検知報告の判定が出るまでの一時対応として、フルパス指定・最小範囲の除外設定は選択肢になるが恒久対応にしてはいけない"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/configure-exclusions-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/exclusion-setting/> ;
    rdf:predicate ks:mayCause ;
    rdf:object <https://comcomponent.com/knowledge/reduced-protection/> ;
    schema:description "除外はDefenderの保護に穴(protection gap)を開ける設定であり、範囲が広いほど保護レベルの低下を招く"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/common-exclusion-mistakes-microsoft-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/defender-for-endpoint/> ;
    rdf:predicate ks:mitigates ;
    rdf:object <https://comcomponent.com/knowledge/false-positive-detection/> ;
    schema:description "EDR導入組織では、顧客側の管理者がDefenderポータルの申請ページから提出し「許可」インジケーターを設定することで組織内の誤検知を抑止できる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/defender-endpoint-false-positives-negatives> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/windows-defender-antivirus/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/msmpeng/> ;
    schema:description "Defenderウイルス対策の実体は、リアルタイム保護を担うMsMpEng.exe(Antimalware Service Executable)というサービスとして動作する"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/microsoft-defender-endpoint-antivirus-performance-mode> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/msmpeng/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/antivirus-minifilter/> ;
    schema:description "MsMpEng.exe(ウイルス対策サービス本体)は、ファイルI/Oを横取りするアンチウイルスミニフィルターを通じてリアルタイムスキャンを行う"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/microsoft-defender-endpoint-antivirus-performance-mode> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/antivirus-minifilter/> ;
    rdf:predicate ks:mayCause ;
    rdf:object <https://comcomponent.com/knowledge/scan-performance-cost/> ;
    schema:description "リアルタイム保護は既定でファイルを開いた時点で同期的にスキャンするため、大量の小さいファイルを開閉するワークロードほどスキャン回数が増え性能コストが上がる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/microsoft-defender-endpoint-antivirus-performance-mode> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/scan-performance-cost/> ;
    rdf:predicate ks:verifiedBy ;
    rdf:object <https://comcomponent.com/knowledge/performance-analyzer/> ;
    schema:description "Windows Defenderでは、どのファイル・プロセスがスキャン負荷の中心かをPerformance analyzer(New-MpPerformanceRecording/Get-MpPerformanceReport)で特定できる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/tune-performance-defender-antivirus> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/dev-drive/> ;
    rdf:predicate ks:uses ;
    rdf:object <https://comcomponent.com/knowledge/defender-performance-mode/> ;
    schema:description "信頼済みのDev Drive上では、Defenderのリアルタイム保護が非同期のパフォーマンスモード(open now, scan later)で既定動作する"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/microsoft-defender-endpoint-antivirus-performance-mode> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/defender-performance-mode/> ;
    rdf:predicate ks:mitigates ;
    rdf:object <https://comcomponent.com/knowledge/scan-performance-cost/> ;
    schema:description "パフォーマンスモードは同期スキャンより高い保護を保ったまま、スキャンによる性能コストを軽減する"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/microsoft-defender-endpoint-antivirus-performance-mode> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/dev-drive/> ;
    rdf:predicate ks:recommendedFor ;
    rdf:object <https://comcomponent.com/knowledge/scan-performance-cost/> ;
    schema:description "開発機のビルド出力やパッケージキャッシュが性能コストの中心なら、それらをDev Driveへ移すのが定石とされる"@ja ;
    ks:evidence <https://learn.microsoft.com/windows/dev-drive/> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "established" .

[] a rdf:Statement ;
    rdf:subject <https://comcomponent.com/knowledge/cpu-throttling-setting/> ;
    rdf:predicate ks:mitigates ;
    rdf:object <https://comcomponent.com/knowledge/scan-performance-cost/> ;
    schema:description "オンデマンドスキャンが業務時間帯に重い場合、-CpuThrottlingやScanAvgCPULoadFactorでスキャンのCPU使用率に上限をかけられる"@ja ;
    ks:evidence <https://learn.microsoft.com/defender-endpoint/mdav-scan-best-practices> ;
    ks:verifiedAt "2026-08-01" ;
    ks:certainty "context-dependent" .
