Microsoft-Windows-Windows Defender

EventTitleChannelSampleRule
101Microsoft Defender Antivirus state updated to hc_stateid.WHCNN
1000Product Name scan has started.OperationalYN
1001Product Name scan has finished.OperationalYN
1002Product Name scan has been stopped before completion.OperationalYN
1003ProductName scan has been paused.OperationalNN
1004ProductName scan has resumed.OperationalNN
1005ProductName scan has encountered an error and terminated.OperationalNN
1006ProductName has detected malware or other potentially unwanted software.OperationalNY
1007ProductName has taken action to protect this machine from malware or other …OperationalNN
1008ProductName has encountered an error when taking action on malware or other …OperationalNN
1009ProductName has restored an item from quarantine.OperationalYY
1010ProductName has encountered an error trying to restore an item from quarantine.OperationalYN
1011ProductName has deleted an item from quarantine.OperationalYN
1012ProductName has encountered an error trying to delete an item from quarantine.OperationalNN
1013Product Name has removed history of malware and other potentially unwanted …OperationalYY
1014ProductName has encountered an error trying to remove history of malware and …OperationalNN
1015ProductName has detected a suspicious behavior.OperationalNY
1116Product Name has detected malware or other potentially unwanted software.OperationalYY
1117Product Name has taken action to protect this machine from malware or other …OperationalYY
1118ProductName has encountered a non-critical error when taking action on malware …OperationalNN
1119ProductName has encountered a critical error when taking action on malware or …OperationalNY
1120ProductName has deduced the hashes for a threat resource.OperationalNN
1121Microsoft Defender Exploit Guard has blocked an operation that is not allowed by …OperationalYY
1122Microsoft Defender Exploit Guard audited an operation that is not allowed by …OperationalYY
1123ProcessName has been blocked from modifying Path by Controlled Folder Access.OperationalNN
1124ProcessName would have been blocked from modifying Path by Controlled Folder …OperationalYN
1125Your IT administrator would have caused Microsoft Defender Exploit Guard to …OperationalYY
1126Your IT administrator has caused Microsoft Defender Exploit Guard to block a …OperationalYY
1127Controlled Folder Access blocked ProcessName from making changes to memory.OperationalNN
1128Controlled Folder Access would have blocked ProcessName from making changes to …OperationalNN
1129A user has allowed a blocked Microsoft Defender Exploit Guard operation.OperationalNY
1130{Product Name} blocked a behavior by {Source app}.OperationalNN
1131ProductName has blocked an operation that your administrator doesn't allow.OperationalNY
1132ProductName has audited an operation.OperationalNY
1133ProductName has blocked an operation that your administrator doesn't allow.OperationalNY
1134ProductName has audited an operation.OperationalNY
1150Endpoint Protection client is up and running in a healthy state.OperationalYN
1151Endpoint Protection client health report (time in UTC).OperationalYY
1160ProductName has detected potentially unwanted application(PUA).OperationalNN
2000Product Name security intelligence version updated.OperationalYN
2001Product Name has encountered an error trying to update security intelligence.OperationalYN
2002Product Name engine version has been updated.OperationalYN
2003ProductName has encountered an error trying to update the engine.OperationalNN
2004ProductName has encountered an error trying to update security intelligence and …OperationalNN
2005ProductName could not load antimalware engine because current platform version …OperationalNN
2006ProductName has encountered an error trying to update the platform.OperationalNN
2007ProductName will soon require a newer platform version to support future …OperationalNN
2008ProductName platform update update to NewPlatformVersion is paused due to system …OperationalNN
2009ProductName platform update to NewPlatformVersion has resumed.OperationalNN
2010Product Name used cloud protection to get additional security intelligence.OperationalYN
2011ProductName used cloud protection to discard obsolete security intelligence …OperationalNN
2012ProductName has encountered an error trying to use cloud protection.OperationalNN
2013ProductName discarded all cloud protection intelligence.OperationalNN
2014Product Name platform update to Product Version has succeeded.OperationalYN
2020{Product Name} downloaded a clean file.OperationalNN
2021{Product Name} has encountered an error trying to download a clean file.OperationalNN
2030ProductName downloaded and configured Microsoft Defender Antivirus (offline …OperationalNN
2031ProductName has encountered an error trying to download and configure Microsoft …OperationalNN
2040The support for your operating system will expire shortly.OperationalNN
2041The support for your operating system has expired.OperationalNN
2042The support for your operating system has expired.OperationalNN
2050Product Name has uploaded a file for further analysis.OperationalYN
2051ProductName has encountered an error trying to upload a suspicious file for …OperationalNN
3000{Product Name} Real-Time Protection agents have started.OperationalNN
3001{Product Name}Real-Time Protection agents have stopped.OperationalNN
3002ProductName Real-Time Protection feature has encountered an error and failed.OperationalYY
3003{Product Name} Real-Time Protection checkpoint has encountered an error and …OperationalNN
3004{Product Name} Real-Time Protection agent has detected changes.OperationalNN
3005{Product Name} Real-Time Protection agent has taken action to protect this …OperationalNN
3006{Product Name} Real-Time Protection agent has encountered an error when taking …OperationalNN
3007ProductName Real-time Protection feature has restarted.OperationalNY
4000{Product Name} AV OnAccess Filter has detected spyware or other potentially …OperationalNN
4002{param1} AV OnAccess Filter has taken action to protect this machine from …OperationalNN
4003{param1} AV OnAccess Filter has encountered an error when taking action on …OperationalNN
5000ProductName Real-time Protection scanning for malware and other potentially …OperationalYN
5001Product Name Real-time Protection scanning for malware and other potentially …OperationalYY
5002{param1} OnAccess scanning for viruses was enabled.OperationalNN
5003{param1} OnAccess scanning for viruses was disabled.OperationalNN
5004Product Name Real-time Protection feature configuration has changed.OperationalYN
5005{Product Name} Real-time Protection checkpoint configuration has changed.OperationalNN
5006{param1} OnAccess filter seems to be a unloaded - OnAccess scanning is disabled …OperationalNN
5007Product Name Configuration has changed.OperationalYY
5008ProductName engine has been terminated due to an unexpected error.OperationalYN
5009ProductName scanning for spyware and other potentially unwanted software has …OperationalNN
5010ProductName scanning for spyware and other potentially unwanted software is …OperationalNY
5011ProductName scanning for viruses has been enabled.OperationalNN
5012ProductName scanning for viruses is disabled.OperationalNY
5013Tamper Protection Changed Type a change to Product Name.OperationalYY
5014ProductName Resource Monitor: Memory consumption exceeded its limit.OperationalNN
5015ProductName Resource Monitor: CPU utilization exceeded its limit.OperationalNN
5016ProductName service seemed to be hung during shutdown.OperationalYN
5017Product Name service feature has encountered an error and failed.OperationalYN
5100{Product Name} has entered a grace period and will soon expire.OperationalNN
5101{Product Name} grace period has expired.OperationalNY

Event ID 101: Microsoft Defender Antivirus state updated to hc_stateid.

#
Channel
WHC

Message #

Microsoft Defender Antivirus state updated to %1.

Fields #

NameDescription
hc_stateid UInt32

References #

Event ID 1000: Product Name scan has started.

#
Channel
Operational
Level
Informational

Message #

%1 scan has started.
 	Scan ID: %3
 	Scan Type: %5
 	Scan Parameters: %7
 	Scan Resources: %11
  	User: %8\%9
 	Scan Trigger: %13
 	Scan Only If Idle: %14
 	Low CPU Priority for Scans: %15
 	Thread Priority: %16

Fields #

NameDescription
Product Name
Product Version
Scan ID
Scan Type Index
Scan Type
Scan Parameters Index
Scan Parameters
Domain UnicodeString
User UnicodeString
SID UnicodeString
Scan Resources
Scan Trigger Index
Scan Trigger
Scan Only If Idle
Low CPU Priority for Scans
Thread Priority
ProductName
ProductVersion
ScanID
ScanTypeIndex
ScanType
ScanParametersIndex
Known values
0
Full Scan
1
Quick Scan
2
Custom Scan
ScanParameters
ScanResources

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:39:31.2640458+00:00",
    "event_record_id": 681,
    "correlation": {},
    "execution": {
      "process_id": 3912,
      "thread_id": 284
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Scan ID": "{831B79B4-9E84-4538-9ED5-8BB6CFFB648D}",
    "Scan Type Index": "1",
    "Scan Type": "Antimalware",
    "Scan Parameters Index": "1",
    "Scan Parameters": "Quick Scan",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Scan Resources": "",
    "Scan Trigger Index": "55",
    "Scan Trigger": "Scheduled maintenance",
    "Scan Only If Idle": "Enabled",
    "Low CPU Priority for Scans": "Disabled",
    "Thread Priority": "7"
  },
  "message": "Microsoft Defender Antivirus scan has started.\r\n \tScan ID: {831B79B4-9E84-4538-9ED5-8BB6CFFB648D}\r\n \tScan Type: Antimalware\r\n \tScan Parameters: Quick Scan\r\n \tScan Resources: \r\n  \tUser: NT AUTHORITY\\SYSTEM\r\n \tScan Trigger: Scheduled maintenance\r\n \tScan Only If Idle: Enabled\r\n \tLow CPU Priority for Scans: Disabled\r\n \tThread Priority: 7"
}

References #

Event ID 1001: Product Name scan has finished.

#
Channel
Operational
Level
Informational

Message #

%1 scan has finished.
 	Scan ID: %3
 	Scan Type: %5
 	Scan Parameters: %7
 	User: %8\%9
 	Scan Time: %11:%12:%13

Fields #

NameDescription
Product Name
Product Version
Scan ID
Scan Type Index
Scan Type
Scan Parameters Index
Scan Parameters
Domain UnicodeString
User UnicodeString
SID UnicodeString
Scan Time Hours
Scan Time Minutes
Scan Time Seconds
ProductName
ProductVersion
ScanID
ScanTypeIndex
ScanType
ScanParametersIndex
Known values
0
Full Scan
1
Quick Scan
2
Custom Scan
ScanParameters
ScanTimeHours
ScanTimeMinutes
ScanTimeSeconds

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:43:05.1284044+00:00",
    "event_record_id": 683,
    "correlation": {
      "ActivityID": "{7CAA8AA4-2C90-4544-BDD8-ED3A22085B41}"
    },
    "execution": {
      "process_id": 3912,
      "thread_id": 284
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Scan ID": "{831B79B4-9E84-4538-9ED5-8BB6CFFB648D}",
    "Scan Type Index": "1",
    "Scan Type": "Antimalware",
    "Scan Parameters Index": "1",
    "Scan Parameters": "Quick Scan",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Scan Time Hours": "0",
    "Scan Time Minutes": "03",
    "Scan Time Seconds": "33"
  },
  "message": "Microsoft Defender Antivirus scan has finished.\r\n \tScan ID: {831B79B4-9E84-4538-9ED5-8BB6CFFB648D}\r\n \tScan Type: Antimalware\r\n \tScan Parameters: Quick Scan\r\n \tUser: NT AUTHORITY\\SYSTEM\r\n \tScan Time: 0:03:33"
}

References #

Event ID 1002: Product Name scan has been stopped before completion.

#
Channel
Operational
Level
Warning

Message #

%1 scan has been stopped before completion.
 	Scan ID: %3
 	Scan Type: %5
 	Scan Parameters: %7
  	User: %8\%9
 	Stop Reason: %12

Fields #

NameDescription
Product Name
Product Version
Scan ID
Scan Type Index
Scan Type
Scan Parameters Index
Scan Parameters
Domain UnicodeString
User UnicodeString
SID UnicodeString
Stop Reason Index
Stop Reason
ProductName
ProductVersion
ScanID
ScanTypeIndex
ScanType
ScanParametersIndex
Known values
0
Full Scan
1
Quick Scan
2
Custom Scan
ScanParameters

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1002,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T08:44:12.4714948+00:00",
    "event_record_id": 644,
    "correlation": {
      "ActivityID": "{2C268CC8-914A-4D21-A104-49C8722B8AD4}"
    },
    "execution": {
      "process_id": 4032,
      "thread_id": 3672
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Scan ID": "{427DEA8A-0CA1-4AEE-9BDD-8E059AA33C24}",
    "Scan Type Index": "1",
    "Scan Type": "Antimalware",
    "Scan Parameters Index": "1",
    "Scan Parameters": "Quick Scan",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Stop Reason Index": "3",
    "Stop Reason": "RPC connection rundown"
  },
  "message": "Microsoft Defender Antivirus scan has been stopped before completion.\r\n \tScan ID: {427DEA8A-0CA1-4AEE-9BDD-8E059AA33C24}\r\n \tScan Type: Antimalware\r\n \tScan Parameters: Quick Scan\r\n  \tUser: NT AUTHORITY\\SYSTEM\r\n \tStop Reason: RPC connection rundown"
}

References #

Event ID 1003: ProductName scan has been paused.

#
Channel
Operational

Message #

%1 scan has been paused.
 	Scan ID: %3
 	Scan Type: %5
 	Scan Parameters: %7
 	User: %8\%9

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
ScanID UnicodeString
ScanTypeIndex UnicodeString
ScanType UnicodeString
ScanParametersIndex UnicodeString
Known values
0
Full Scan
1
Quick Scan
2
Custom Scan
ScanParameters UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString

References #

Event ID 1004: ProductName scan has resumed.

#
Channel
Operational

Message #

%1 scan has resumed.
 	Scan ID: %3
  	Scan Type: %5
 	Scan Parameters: %7
 	User: %8\%9

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
ScanID UnicodeString
ScanTypeIndex UnicodeString
ScanType UnicodeString
ScanParametersIndex UnicodeString
Known values
0
Full Scan
1
Quick Scan
2
Custom Scan
ScanParameters UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString

References #

Event ID 1005: ProductName scan has encountered an error and terminated.

#
Channel
Operational
Collection Priority
Recommended (NSA, others)

Message #

%1 scan has encountered an error and terminated.
 	Scan ID: %3
 	Scan Type: %5
 	Scan Parameters: %7
 	User: %8\%9
 	Error Code: %11
 	Error description: %12

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
ScanID UnicodeString
ScanTypeIndex UnicodeString
ScanType UnicodeString
ScanParametersIndex UnicodeString
Known values
0
Full Scan
1
Quick Scan
2
Custom Scan
ScanParameters UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString

References #

Event ID 1006: ProductName has detected malware or other potentially unwanted software.

#
Channel
Operational
Collection Priority
Recommended (Olaf Hartong, others)

Message #

%1 has detected malware or other potentially unwanted software.
 For more information please see the following:
%15
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	Path Found: %16
 	Detection Type: %22
 	Detection Source: %5
 	Status: %20
 	User: %8\%9
 	Process Name: %7
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
DetectionSourceIndex UnicodeString
DetectionSource UnicodeString
Unused UnicodeString
ProcessName UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
FWLink UnicodeString
PathFound UnicodeString
DetectionOriginIndex UnicodeString
DetectionOrigin UnicodeString
ExecutionStatusIndex UnicodeString
ExecutionStatus UnicodeString
DetectionTypeIndex UnicodeString
DetectionType UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1007: ProductName has taken action to protect this machine from malware or other potentially unwanted software.

#
Channel
Operational
Collection Priority
Recommended (ANSSI, others)

Message #

%1 has taken action to protect this machine from malware or other potentially unwanted software.
 For more information please see the following:
%15
 	User: %8\%9
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	Action: %20
 	Status: %7
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
Unused UnicodeString
Unused2 UnicodeString
StatusCode UnicodeStringNTSTATUS reference
StatusDescription UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
FWLink UnicodeString
Path UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
CleaningActionIndex UnicodeString
CleaningAction UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
Unused7 UnicodeString
Unused8 UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1008: ProductName has encountered an error when taking action on malware or other potentially unwanted software.

#
Channel
Operational
Collection Priority
Recommended (Olaf Hartong, others)

Message #

%1 has encountered an error when taking action on malware or other potentially unwanted software.
 For more information please see the following:
%15
 	User: %8\%9
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	Path: %16
 	Action: %20
 	Error Code: %21
 	Error description: %22
 	Status: %7
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
Unused UnicodeString
Unused2 UnicodeString
StatusCode UnicodeStringNTSTATUS reference
StatusDescription UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
FWLink UnicodeString
Path UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
CleaningActionIndex UnicodeString
CleaningAction UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1009: ProductName has restored an item from quarantine.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)

Message #

%1 has restored an item from quarantine.
 For more information please see the following:
%15
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	User: %8\%9
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
Product Name
Product Version
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Unused5 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
Threat Name
Threat ID
Severity ID
Category ID
FWLink UnicodeString
Path UnicodeString
Unused6 UnicodeString
Unused7 UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
Unused11 UnicodeString
Unused12 UnicodeString
Unused13 UnicodeString
Severity Name
Category Name
Security intelligence Version
Engine Version
ProductName UnicodeString
ProductVersion UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1009,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T15:47:15.1238364+00:00",
    "event_record_id": 6506,
    "correlation": {
      "ActivityID": "{5F95AD28-CAF8-4C6F-A387-C8C9D4B25B47}"
    },
    "execution": {
      "process_id": 3360,
      "thread_id": 1260
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Unused4": "",
    "Unused5": "",
    "Domain": "ludus",
    "User": "domainadmin",
    "SID": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "Threat Name": "HackTool:JS/Jsprat",
    "Threat ID": "2147708292",
    "Severity ID": "4",
    "Category ID": "34",
    "FWLink": "https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:JS/Jsprat&threatid=2147708292&enterprise=0",
    "Path": "file:_C:\\Users\\domainadmin\\AppData\\Local\\Temp\\atmp\\atomic-red-team-master\\atomics\\T1505.003\\src\\b.jsp; file:_C:\\Users\\domainadmin\\AppData\\Local\\Temp\\atomics.zip",
    "Unused6": "",
    "Unused7": "",
    "Unused8": "",
    "Unused9": "",
    "Unused10": "",
    "Unused11": "",
    "Unused12": "",
    "Unused13": "",
    "Severity Name": "High",
    "Category Name": "Tool",
    "Security intelligence Version": "AV: 1.451.182.0, AS: 1.451.182.0",
    "Engine Version": "1.1.26040.8"
  },
  "message": "Microsoft Defender Antivirus has restored an item from quarantine.\r\n For more information please see the following:\r\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:JS/Jsprat&threatid=2147708292&enterprise=0\r\n \tName: HackTool:JS/Jsprat\r\n \tID: 2147708292\r\n \tSeverity: High\r\n \tCategory: Tool\r\n \tUser: ludus\\domainadmin\r\n \tSecurity intelligence Version: AV: 1.451.182.0, AS: 1.451.182.0\r\n \tEngine Version: 1.1.26040.8"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 1010: ProductName has encountered an error trying to restore an item from quarantine.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (NSA, others)

Message #

%1 has encountered an error trying to restore an item from quarantine.
 For more information please see the following:
%15
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	User: %8\%9
 	Error Code: %3
 	Error description: %4
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
Product Name
Product Version
Error Code
Error Description
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
Threat Name
Threat ID
Severity ID
Category ID
FWLink UnicodeString
Path UnicodeString
Unused4 UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
Unused7 UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
Unused11 UnicodeString
Severity Name
Category Name
Security intelligence Version
Engine Version
ProductName UnicodeString
ProductVersion UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78",
    "event_source_name": "",
    "event_id": 1010,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-30T16:09:40.5005064+00:00",
    "event_record_id": 6797,
    "correlation": {
      "ActivityID": "ca465ba4-7793-4c27-8a4f-7f4cb016bb42",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3360,
      "thread_id": 7916
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Error Code": "0x80508014",
    "Error Description": "The quarantined item cannot be restored. ",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Domain": "ludus",
    "User": "domainadmin",
    "SID": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "Threat Name": "Trojan:PowerShell/PowRun.DA!ams",
    "Threat ID": "2147937660",
    "Severity ID": "5",
    "Category ID": "8",
    "FWLink": "https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:PowerShell/PowRun.DA!ams&threatid=2147937660&enterprise=0",
    "Path": "file:_C:\\AtomicRedTeam\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1071.001\\T1071.001.md",
    "Unused4": "",
    "Unused5": "",
    "Unused6": "",
    "Unused7": "",
    "Unused8": "",
    "Unused9": "",
    "Unused10": "",
    "Unused11": "",
    "Severity Name": "Severe",
    "Category Name": "Trojan",
    "Security intelligence Version": "AV: 1.451.182.0, AS: 1.451.182.0",
    "Engine Version": "1.1.26040.8"
  },
  "message": "Microsoft Defender Antivirus has encountered an error trying to restore an item from quarantine.\r\n For more information please see the following:\r\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:PowerShell/PowRun.DA!ams&threatid=2147937660&enterprise=0\r\n \tName: Trojan:PowerShell/PowRun.DA!ams\r\n \tID: 2147937660\r\n \tSeverity: Severe\r\n \tCategory: Trojan\r\n \tUser: ludus\\domainadmin\r\n \tError Code: 0x80508014\r\n \tError description: The quarantined item cannot be restored. \r\n \tSecurity intelligence Version: AV: 1.451.182.0, AS: 1.451.182.0\r\n \tEngine Version: 1.1.26040.8"
}

References #

Event ID 1011: ProductName has deleted an item from quarantine.

#
Channel
Operational
Level
Informational

Message #

%1 has deleted an item from quarantine.
 For more information please see the following:
%15
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	User: %8\%9
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
Product Name
Product Version
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Unused5 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
Threat Name
Threat ID
Severity ID
Category ID
FWLink UnicodeString
Path UnicodeString
Unused6 UnicodeString
Unused7 UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
Unused11 UnicodeString
Unused12 UnicodeString
Unused13 UnicodeString
Severity Name
Category Name
Security intelligence Version
Engine Version
ProductName UnicodeString
ProductVersion UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1011,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T02:07:21.9451408+00:00",
    "event_record_id": 6151,
    "correlation": {},
    "execution": {
      "process_id": 6760,
      "thread_id": 12460
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Unused4": "",
    "Unused5": "",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Threat Name": "Trojan:Win32/Wacatac.H!ml",
    "Threat ID": "2147814523",
    "Severity ID": "5",
    "Category ID": "8",
    "FWLink": "https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0",
    "Path": "file:_C:\\Users\\domainuser\\Downloads\\finance - Copy.scr",
    "Unused6": "",
    "Unused7": "",
    "Unused8": "",
    "Unused9": "",
    "Unused10": "",
    "Unused11": "",
    "Unused12": "",
    "Unused13": "",
    "Severity Name": "Severe",
    "Category Name": "Trojan",
    "Security intelligence Version": "AV: 1.451.173.0, AS: 1.451.173.0",
    "Engine Version": "1.1.26040.8"
  },
  "message": "Microsoft Defender Antivirus has deleted an item from quarantine.\r\n For more information please see the following:\r\nhttps://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Wacatac.H!ml&threatid=2147814523&enterprise=0\r\n \tName: Trojan:Win32/Wacatac.H!ml\r\n \tID: 2147814523\r\n \tSeverity: Severe\r\n \tCategory: Trojan\r\n \tUser: NT AUTHORITY\\SYSTEM\r\n \tSecurity intelligence Version: AV: 1.451.173.0, AS: 1.451.173.0\r\n \tEngine Version: 1.1.26040.8"
}

References #

Event ID 1012: ProductName has encountered an error trying to delete an item from quarantine.

#
Channel
Operational

Message #

%1 has encountered an error trying to delete an item from quarantine.
 For more information please see the following:
%15
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	User: %8\%9
 	Error Code: %3
 	Error description: %4
 	Security intelligence Version: %27
 	Engine Version: %28

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
FWLink UnicodeString
Path UnicodeString
Unused4 UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
Unused7 UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
Unused11 UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1013: Product Name has removed history of malware and other potentially unwanted software.

#
Channel
Operational
Level
Informational

Message #

%1 has removed history of malware and other potentially unwanted software.
 	Time: %3
 	User: %8\%9

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Timestamp UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 1013,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-09T18:07:25.039591+00:00",
    "event_record_id": 1344,
    "correlation": {},
    "execution": {
      "process_id": 3784,
      "thread_id": 1608
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26010.5",
    "Timestamp": "2026-02-22T18:07:23Z",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Unused4": "",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18"
  },
  "message": ""
}

Example keys not documented in the fields table: Product Name, Product Version

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 1014: ProductName has encountered an error trying to remove history of malware and other potentially unwanted software.

#
Channel
Operational

Message #

%1 has encountered an error trying to remove history of malware and other potentially unwanted software.
 	Time: %3
 	User: %8\%9
 	Error Code: %4
 	Error description: %5

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Timestamp UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString

References #

Event ID 1015: ProductName has detected a suspicious behavior.

#
Channel
Operational

Message #

%1 has detected a suspicious behavior.
 	Name: %11
 	ID: %12
 	Severity: %25
 	Category: %26
 	Path Found: %16
 	Detection Origin: %18
 	Detection Type: %22
 	Detection Source: %5
 	Status: %20
 	User: %8\%9
 	Process Name: %7
 	Security intelligence ID: %30
 	Security intelligence Version: %27
 	Engine Version: %28
 	Fidelity Label: %32
 	Target File Name: %36

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
DetectionSourceIndex UnicodeString
DetectionSource UnicodeString
Unused UnicodeString
ProcessName UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ThreatName UnicodeString
ThreatID UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
CategoryID UnicodeString
FWLink UnicodeString
PathFound UnicodeString
DetectionOriginIndex UnicodeString
DetectionOrigin UnicodeString
ExecutionStatusIndex UnicodeString
ExecutionStatus UnicodeString
DetectionTypeIndex UnicodeString
DetectionType UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
SeverityName UnicodeString
CategoryName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString
ProcessID UnicodeString
SecurityintelligenceID UnicodeString
FidelityValue UnicodeString
FidelityLabel UnicodeString
ImageFileHash UnicodeString
Unused4 UnicodeString
Unused5 UnicodeString
TargetFileName UnicodeString
TargetFileHash UnicodeString

References #

Event ID 1116: Product Name has detected malware or other potentially unwanted software.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Olaf Hartong, others)

Message #

%1 has detected malware or other potentially unwanted software.
 For more information please see the following:
%13
 	Name: %8
 	ID: %7
 	Severity: %10
 	Category: %12
 	Path: %22
 	Detection Origin: %24
 	Detection Type: %28
 	Detection Source: %18
 	User: %20
 	Process Name: %19
 	Security intelligence Version: %41
 	Engine Version: %42

Fields #

NameDescriptionRules
ProductName
ProductVersion
DetectionID
DetectionTime
Unused UnicodeString
Unused2 UnicodeString
ThreatID
ThreatName
SeverityID
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
SeverityName
CategoryID
CategoryName
FWLink UnicodeString
StatusCodeNTSTATUS reference
StatusDescription
State UnicodeString
SourceID
Known values
0
Unknown
1
User - user initiated scan
2
System - system initiated scan
3
Real-time - real-time protection component
4
IOAV - IE Downloads and Outlook Express Attachments
5
NIS - Network Inspection System
7
ELAM - Early Launch Antimalware (boot sequence)
8
Local attestation
9
Remote attestation
SourceName1 detection rule
ProcessName
DetectionUser
Unused3 UnicodeString
Path UnicodeString
OriginID
Known values
0
Unknown
1
Local machine
2
Network share
3
Internet
4
Incoming traffic
5
Outgoing traffic
OriginName
ExecutionID
ExecutionName
TypeID
TypeName
PreExecutionStatus
ActionID
Known values
1
Clean - the resource was cleaned
2
Quarantine - the resource was quarantined
3
Remove - the resource was deleted
6
Allow - the resource was allowed to execute/exist
8
User defined - action determined by user policy
9
NoAction - no action taken (detection only; matches MSFT_MpPreference value 9 NoAction)
10
Block - the resource was blocked from executing
ActionName
Unused4 UnicodeString
ErrorCode
ErrorDescription
Unused5 UnicodeString
PostCleanStatus
AdditionalActionsID
AdditionalActionsString
RemediationUser
Unused6 UnicodeString
SecurityintelligenceVersion
EngineVersion

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 1116,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2019-07-18T20:51:50.798995+00:00",
    "event_record_id": 102,
    "correlation": {
      "ActivityID": "40013F0F-EF76-4940-A8B2-4DE50BE9AAC3"
    },
    "execution": {
      "process_id": 6024,
      "thread_id": 6068
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "%%827",
    "Product Version": "4.18.1906.3",
    "Detection ID": "{37522D93-EBDD-4A5B-93B6-E984C9E3FD38}",
    "Detection Time": "2019-07-18T20:40:16.697Z",
    "Unused": "",
    "Unused2": "",
    "Threat ID": "2147708292",
    "Threat Name": "HackTool:JS/Jsprat",
    "Severity ID": "4",
    "Severity Name": "High",
    "Category ID": "34",
    "Category Name": "Tool",
    "FWLink": "https://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:JS/Jsprat&threatid=2147708292&enterprise=0",
    "Status Code": "1",
    "Status Description": "",
    "State": "1",
    "Source ID": "3",
    "Source Name": "%%818",
    "Process Name": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "Detection User": "MSEDGEWIN10\\IEUser",
    "Unused3": "",
    "Path": "containerfile:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1100\\shells\\b.jsp; file:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1100\\shells\\b.jsp->(SCRIPT0005); file:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1100\\shells\\b.jsp->(SCRIPT0037); file:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1100\\shells\\b.jsp->(SCRIPT0045); file:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1100\\shells\\b.jsp->(SCRIPT0065); file:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1100\\shells\\b.jsp->(SCRIPT0068)",
    "Origin ID": "1",
    "Origin Name": "%%845",
    "Execution ID": "1",
    "Execution Name": "%%813",
    "Type ID": "8",
    "Type Name": "%%862",
    "Pre Execution Status": "0",
    "Action ID": "9",
    "Action Name": "%%887",
    "Unused4": "",
    "Error Code": "0x00000000",
    "Error Description": "The operation completed successfully. ",
    "Unused5": "",
    "Post Clean Status": "0",
    "Additional Actions ID": "0",
    "Additional Actions String": "No additional actions required",
    "Remediation User": "",
    "Unused6": "",
    "Signature Version": "AV: 1.297.1333.0, AS: 1.297.1333.0, NIS: 0.0.0.0",
    "Engine Version": "AM: 1.1.16100.4, NIS: 0.0.0.0"
  },
  "message": ""
}

Example keys not documented in the fields table: Action ID, Action Name, Additional Actions ID, Additional Actions String, Category ID, Category Name, Detection ID, Detection Time, Detection User, Engine Version, Error Code, Error Description, Execution ID, Execution Name, Origin ID, Origin Name, Post Clean Status, Pre Execution Status, Process Name, Product Name, Product Version, Remediation User, Severity ID, Severity Name, Signature Version, Source ID, Source Name, Status Code, Status Description, Threat ID, Threat Name, Type ID, Type Name

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 1117: Product Name has taken action to protect this machine from malware or other potentially unwanted software.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Olaf Hartong, others)

Message #

%1 has taken action to protect this machine from malware or other potentially unwanted software.
 For more information please see the following:
%13
 	Name: %8
 	ID: %7
 	Severity: %10
 	Category: %12
 	Path: %22
 	Detection Origin: %24
 	Detection Type: %28
 	Detection Source: %18
 	User: %39
 	Process Name: %19
 	Action: %31
 	Action Status: %38
 	Error Code: %33
 	Error description: %34
 	Security intelligence Version: %41
 	Engine Version: %42

Fields #

NameDescription
ProductName
ProductVersion
DetectionID
DetectionTime
Unused UnicodeString
Unused2 UnicodeString
ThreatID
ThreatName
SeverityID
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
SeverityName
CategoryID
CategoryName
FWLink UnicodeString
StatusCodeNTSTATUS reference
StatusDescription
State UnicodeString
SourceID
Known values
0
Unknown
1
User - user initiated scan
2
System - system initiated scan
3
Real-time - real-time protection component
4
IOAV - IE Downloads and Outlook Express Attachments
5
NIS - Network Inspection System
7
ELAM - Early Launch Antimalware (boot sequence)
8
Local attestation
9
Remote attestation
SourceName
ProcessName
DetectionUser
Unused3 UnicodeString
Path UnicodeString
OriginID
Known values
0
Unknown
1
Local machine
2
Network share
3
Internet
4
Incoming traffic
5
Outgoing traffic
OriginName
ExecutionID
ExecutionName
TypeID
TypeName
PreExecutionStatus
ActionID
Known values
1
Clean - the resource was cleaned
2
Quarantine - the resource was quarantined
3
Remove - the resource was deleted
6
Allow - the resource was allowed to execute/exist
8
User defined - action determined by user policy
9
NoAction - no action taken (detection only; matches MSFT_MpPreference value 9 NoAction)
10
Block - the resource was blocked from executing
ActionName
Unused4 UnicodeString
ErrorCode
ErrorDescription
Unused5 UnicodeString
PostCleanStatus
AdditionalActionsID
AdditionalActionsString
RemediationUser
Unused6 UnicodeString
SecurityintelligenceVersion
EngineVersion

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 1117,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2019-07-18T20:53:31.952569+00:00",
    "event_record_id": 106,
    "correlation": {
      "ActivityID": "2AD0CF94-C382-4568-A488-1253A4ED0F54"
    },
    "execution": {
      "process_id": 6024,
      "thread_id": 6068
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "%%827",
    "Product Version": "4.18.1906.3",
    "Detection ID": "{8791B1FB-0FE7-412E-B084-524CB5A221F3}",
    "Detection Time": "2019-07-18T20:40:13.775Z",
    "Unused": "",
    "Unused2": "",
    "Threat ID": "2147735426",
    "Threat Name": "Trojan:XML/Exeselrun.gen!A",
    "Severity ID": "5",
    "Severity Name": "Severe",
    "Category ID": "8",
    "Category Name": "Trojan",
    "FWLink": "https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:XML/Exeselrun.gen!A&threatid=2147735426&enterprise=0",
    "Status Code": "5",
    "Status Description": "",
    "State": "2",
    "Source ID": "3",
    "Source Name": "%%818",
    "Process Name": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "Detection User": "MSEDGEWIN10\\IEUser",
    "Unused3": "",
    "Path": "file:_C:\\AtomicRedTeam\\atomic-red-team-master\\atomics\\T1086\\payloads\\test.xsl",
    "Origin ID": "1",
    "Origin Name": "%%845",
    "Execution ID": "1",
    "Execution Name": "%%813",
    "Type ID": "2",
    "Type Name": "%%823",
    "Pre Execution Status": "0",
    "Action ID": "6",
    "Action Name": "%%811",
    "Unused4": "",
    "Error Code": "0x80508023",
    "Error Description": "The program could not find the malware and other potentially unwanted software on this device. ",
    "Unused5": "",
    "Post Clean Status": "0",
    "Additional Actions ID": "0",
    "Additional Actions String": "No additional actions required",
    "Remediation User": "NT AUTHORITY\\SYSTEM",
    "Unused6": "",
    "Signature Version": "AV: 1.297.1333.0, AS: 1.297.1333.0, NIS: 0.0.0.0",
    "Engine Version": "AM: 1.1.16100.4, NIS: 0.0.0.0"
  },
  "message": ""
}

Example keys not documented in the fields table: Action ID, Action Name, Additional Actions ID, Additional Actions String, Category ID, Category Name, Detection ID, Detection Time, Detection User, Engine Version, Error Code, Error Description, Execution ID, Execution Name, Origin ID, Origin Name, Post Clean Status, Pre Execution Status, Process Name, Product Name, Product Version, Remediation User, Severity ID, Severity Name, Signature Version, Source ID, Source Name, Status Code, Status Description, Threat ID, Threat Name, Type ID, Type Name

References #

Event ID 1118: ProductName has encountered a non-critical error when taking action on malware or other potentially unwanted software.

#
Channel
Operational
Collection Priority
Recommended (ANSSI, others)

Message #

%1 has encountered a non-critical error when taking action on malware or other potentially unwanted software.
 For more information please see the following:
%13
 	Name: %8
 	ID: %7
 	Severity: %10
 	Category: %12
 	Path: %22
 	Detection Origin: %24
 	Detection Type: %28
 	Detection Source: %18
 	User: %39
 	Process Name: %19
 	Action: %31
 	Action Status: %38
 	Error Code: %33
 	Error description: %34
 	Security intelligence Version: %41
 	Engine Version: %42

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
DetectionTime UnicodeString
Unused UnicodeString
Unused2 UnicodeString
ThreatID UnicodeString
ThreatName UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
SeverityName UnicodeString
CategoryID UnicodeString
CategoryName UnicodeString
FWLink UnicodeString
StatusCode UnicodeStringNTSTATUS reference
StatusDescription UnicodeString
State UnicodeString
SourceID UnicodeString
Known values
0
Unknown
1
User - user initiated scan
2
System - system initiated scan
3
Real-time - real-time protection component
4
IOAV - IE Downloads and Outlook Express Attachments
5
NIS - Network Inspection System
7
ELAM - Early Launch Antimalware (boot sequence)
8
Local attestation
9
Remote attestation
SourceName UnicodeString
ProcessName UnicodeString
DetectionUser UnicodeString
Unused3 UnicodeString
Path UnicodeString
OriginID UnicodeString
Known values
0
Unknown
1
Local machine
2
Network share
3
Internet
4
Incoming traffic
5
Outgoing traffic
OriginName UnicodeString
ExecutionID UnicodeString
ExecutionName UnicodeString
TypeID UnicodeString
TypeName UnicodeString
PreExecutionStatus UnicodeString
ActionID UnicodeString
Known values
1
Clean - the resource was cleaned
2
Quarantine - the resource was quarantined
3
Remove - the resource was deleted
6
Allow - the resource was allowed to execute/exist
8
User defined - action determined by user policy
9
NoAction - no action taken (detection only; matches MSFT_MpPreference value 9 NoAction)
10
Block - the resource was blocked from executing
ActionName UnicodeString
Unused4 UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused5 UnicodeString
PostCleanStatus UnicodeString
AdditionalActionsID UnicodeString
AdditionalActionsString UnicodeString
RemediationUser UnicodeString
Unused6 UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1119: ProductName has encountered a critical error when taking action on malware or other potentially unwanted software.

#
Channel
Operational
Collection Priority
Recommended (ANSSI, others)

Message #

%1 has encountered a critical error when taking action on malware or other potentially unwanted software.
 For more information please see the following:
%13
 	Name: %8
 	ID: %7
 	Severity: %10
 	Category: %12
 	Path: %22
 	Detection Origin: %24
 	Detection Type: %28
 	Detection Source: %18
 	User: %39
 	Process Name: %19
 	Action: %31
 	Action Status: %38
 	Error Code: %33
 	Error description: %34
 	Security intelligence Version: %41
 	Engine Version: %42

Fields #

NameDescriptionRules
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
DetectionTime UnicodeString
Unused UnicodeString
Unused2 UnicodeString
ThreatID UnicodeString
ThreatName UnicodeString1 detection rule
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
SeverityName UnicodeString
CategoryID UnicodeString
CategoryName UnicodeString
FWLink UnicodeString
StatusCode UnicodeStringNTSTATUS reference
StatusDescription UnicodeString
State UnicodeString
SourceID UnicodeString
Known values
0
Unknown
1
User - user initiated scan
2
System - system initiated scan
3
Real-time - real-time protection component
4
IOAV - IE Downloads and Outlook Express Attachments
5
NIS - Network Inspection System
7
ELAM - Early Launch Antimalware (boot sequence)
8
Local attestation
9
Remote attestation
SourceName UnicodeString1 detection rule
ProcessName UnicodeString1 detection rule
DetectionUser UnicodeString
Unused3 UnicodeString
Path UnicodeString1 detection rule
OriginID UnicodeString
Known values
0
Unknown
1
Local machine
2
Network share
3
Internet
4
Incoming traffic
5
Outgoing traffic
OriginName UnicodeString
ExecutionID UnicodeString
ExecutionName UnicodeString
TypeID UnicodeString
TypeName UnicodeString
PreExecutionStatus UnicodeString
ActionID UnicodeString
Known values
1
Clean - the resource was cleaned
2
Quarantine - the resource was quarantined
3
Remove - the resource was deleted
6
Allow - the resource was allowed to execute/exist
8
User defined - action determined by user policy
9
NoAction - no action taken (detection only; matches MSFT_MpPreference value 9 NoAction)
10
Block - the resource was blocked from executing
ActionName UnicodeString
Unused4 UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused5 UnicodeString
PostCleanStatus UnicodeString
AdditionalActionsID UnicodeString
AdditionalActionsString UnicodeString
RemediationUser UnicodeString
Unused6 UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

  • RedSun - TieringEngineService.exe Detected as EICAR Test File source critical: Detects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe dropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present. This covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based AV bypass/privilege escalation tool. RedSun works as follows: 1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\RS-{GUID}
    2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger a Defender scan and remediation attempt 3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file 4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open 5. During the oplock break window, RedSun swaps the mount point (junction) to redirect \?\C:\Windows\System32 to the attacker-controlled temp path 6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges
    T1036, T1036.005, T1055, T1685

References #

Event ID 1120: ProductName has deduced the hashes for a threat resource.

#
Channel
Operational
Collection Priority
Recommended (ANSSI)

Message #

%1 has deduced the hashes for a threat resource.
 	Current Platform Version: %2
 	Threat resource path: %4
 	Hashes: %5

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
Threatresourcepath UnicodeString
Hashes UnicodeString

References #

Event ID 1121: Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (JSCU-NL)

Message #

Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
 For more information please contact your IT administrator.
 	ID: %4
 	Detection time: %5
 	User: %6
 	Path: %7
 	Process Name: %8
 	Target Commandline: %12
 	Parent Commandline: %13
 	Involved File: %14
 	Inheritance Flags: %15
 	Security intelligence Version: %9
 	Engine Version: %10
 	Product Version: %2

Fields #

NameDescriptionRules
Product Name
Product Version
Unused UnicodeString
ID UnicodeString
Detection Time
User UnicodeString
Path UnicodeString1 detection rule
Process Name
Security intelligence Version
Engine Version
RuleType UnicodeString
Target Commandline
Parent Commandline
Involved File
Inhertiance Flags
ProductName UnicodeString
ProductVersion UnicodeString
DetectionTime UnicodeString
ProcessName UnicodeString17 detection rules
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString
TargetCommandline UnicodeString
ParentCommandline UnicodeString
InvolvedFile UnicodeString
InhertianceFlags UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1121,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T14:15:36.1622673+00:00",
    "event_record_id": 6305,
    "correlation": {
      "ActivityID": "{5DF4E046-A28D-4FBE-B553-6C83E2B1A15D}"
    },
    "execution": {
      "process_id": 3292,
      "thread_id": 3176
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Unused": "",
    "ID": "D1E49AAC-8F56-4280-B9BA-993A6D77406C",
    "Detection Time": "2026-05-30T14:15:36.161Z",
    "User": "NT AUTHORITY\\NETWORK SERVICE",
    "Path": "C:\\Windows\\System32\\cmd.exe",
    "Process Name": "C:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
    "Security intelligence Version": "1.451.175.0",
    "Engine Version": "1.1.26040.8",
    "RuleType": "ENT\\ConsR",
    "Target Commandline": "cmd.exe /c echo EVTGEN-ASR-PROBE > %TEMP%\\evtgen_asr_probe.txt",
    "Parent Commandline": "C:\\Windows\\system32\\wbem\\wmiprvse.exe",
    "Involved File": "",
    "Inhertiance Flags": "0x00000000"
  },
  "message": "Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.\r\n For more information please contact your IT administrator.\r\n \tID: D1E49AAC-8F56-4280-B9BA-993A6D77406C\r\n \tDetection time: 2026-05-30T14:15:36.161Z\r\n \tUser: NT AUTHORITY\\NETWORK SERVICE\r\n \tPath: C:\\Windows\\System32\\cmd.exe\r\n \tProcess Name: C:\\Windows\\System32\\wbem\\WmiPrvSE.exe\r\n \tTarget Commandline: cmd.exe /c echo EVTGEN-ASR-PROBE > %TEMP%\\evtgen_asr_probe.txt\r\n \tParent Commandline: C:\\Windows\\system32\\wbem\\wmiprvse.exe\r\n \tInvolved File: \r\n \tInheritance Flags: 0x00000000\r\n \tSecurity intelligence Version: 1.451.175.0\r\n \tEngine Version: 1.1.26040.8\r\n \tProduct Version: 4.18.26040.7\r\n"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
process_nameends_with\wmiprvse.exe1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Kusto # view in coverage

References #

Event ID 1122: Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (JSCU-NL)

Message #

Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.
 For more information please contact your IT administrator.
 	ID: %4
 	Detection time: %5
 	User: %6
 	Path: %7
 	Process Name: %8
 	Target Commandline: %12
 	Parent Commandline: %13
 	Involved File: %14
 	Inheritance Flags: %15
 	Security intelligence Version: %9
 	Engine Version: %10
 	Product Version: %2

Fields #

NameDescription
Product Name
Product Version
Unused UnicodeString
ID UnicodeString
Detection Time
User UnicodeString
Path UnicodeString
Process Name
Security intelligence Version
Engine Version
RuleType UnicodeString
Target Commandline
Parent Commandline
Involved File
Inhertiance Flags
ProductName UnicodeString
ProductVersion UnicodeString
DetectionTime UnicodeString
ProcessName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString
TargetCommandline UnicodeString
ParentCommandline UnicodeString
InvolvedFile UnicodeString
InhertianceFlags UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1122,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T14:15:28.0001329+00:00",
    "event_record_id": 6303,
    "correlation": {
      "ActivityID": "{5B69B6E9-CBF9-405A-9315-5D2CC183345E}"
    },
    "execution": {
      "process_id": 3292,
      "thread_id": 3176
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Unused": "",
    "ID": "D1E49AAC-8F56-4280-B9BA-993A6D77406C",
    "Detection Time": "2026-05-30T14:15:27.999Z",
    "User": "ludus\\domainadmin",
    "Path": "C:\\Windows\\System32\\conhost.exe",
    "Process Name": "C:\\Windows\\System32\\cmd.exe",
    "Security intelligence Version": "1.451.175.0",
    "Engine Version": "1.1.26040.8",
    "RuleType": "ENT\\ConsR",
    "Target Commandline": "\\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1",
    "Parent Commandline": "cmd.exe /c echo EVTGEN-ASR-PROBE > %TEMP%\\evtgen_asr_probe.txt",
    "Involved File": "",
    "Inhertiance Flags": "0x00000001"
  },
  "message": "Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.\r\n For more information please contact your IT administrator.\r\n \tID: D1E49AAC-8F56-4280-B9BA-993A6D77406C\r\n \tDetection time: 2026-05-30T14:15:27.999Z\r\n \tUser: ludus\\domainadmin\r\n \tPath: C:\\Windows\\System32\\conhost.exe\r\n \tProcess Name: C:\\Windows\\System32\\cmd.exe\r\n \tTarget Commandline: \\??\\C:\\Windows\\system32\\conhost.exe 0xffffffff -ForceV1\r\n \tParent Commandline: cmd.exe /c echo EVTGEN-ASR-PROBE > %TEMP%\\evtgen_asr_probe.txt\r\n \tInvolved File: \r\n \tInheritance Flags: 0x00000001\r\n \tSecurity intelligence Version: 1.451.175.0\r\n \tEngine Version: 1.1.26040.8\r\n \tProduct Version: 4.18.26040.7\r\n"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

References #

Event ID 1123: ProcessName has been blocked from modifying Path by Controlled Folder Access.

#
Channel
Operational
Collection Priority
Recommended (JSCU-NL)

Message #

%8 has been blocked from modifying %7 by Controlled Folder Access.
 	Detection time: %5
 	User: %6
 	Path: %7
 	Process Name: %8
 	Security intelligence Version: %9
 	Engine Version: %10
 	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ID UnicodeString
DetectionTime UnicodeString
User UnicodeString
Path UnicodeString
ProcessName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1124: ProcessName would have been blocked from modifying Path by Controlled Folder Access.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (JSCU-NL)

Message #

%8 would have been blocked from modifying %7 by Controlled Folder Access.
 	Detection time: %5
 	User: %6
 	Path: %7
 	Process Name: %8
 	Security intelligence Version: %9
 	Engine Version: %10
 	Product Version: %2

Fields #

NameDescription
Product Name
Product Version
Unused UnicodeString
ID UnicodeString
Detection Time
User UnicodeString
Path UnicodeString
Process Name
Security intelligence Version
Engine Version
ProductName UnicodeString
ProductVersion UnicodeString
DetectionTime UnicodeString
ProcessName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1124,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T14:16:09.9021147+00:00",
    "event_record_id": 6333,
    "correlation": {
      "ActivityID": "{FDAB464D-5EBD-496A-8447-DBFEED1DFCF6}"
    },
    "execution": {
      "process_id": 3292,
      "thread_id": 8224
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Unused": "",
    "ID": "",
    "Detection Time": "2026-05-30T14:16:09.900Z",
    "User": "ludus\\domainadmin",
    "Path": "%userprofile%\\Documents\\",
    "Process Name": "C:\\Windows\\System32\\wsmprovhost.exe",
    "Security intelligence Version": "1.451.175.0",
    "Engine Version": "1.1.26040.8"
  },
  "message": "C:\\Windows\\System32\\wsmprovhost.exe would have been blocked from modifying %userprofile%\\Documents\\ by Controlled Folder Access.\r\n \tDetection time: 2026-05-30T14:16:09.900Z\r\n \tUser: ludus\\domainadmin\r\n \tPath: %userprofile%\\Documents\\\r\n \tProcess Name: C:\\Windows\\System32\\wsmprovhost.exe\r\n \tSecurity intelligence Version: 1.451.175.0\r\n \tEngine Version: 1.1.26040.8\r\n \tProduct Version: 4.18.26040.7\r\n"
}

References #

Event ID 1125: Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (JSCU-NL)

Message #

Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.
 	Detection time: %4
 	User: %5
 	Destination: %6
 	Process Name: %7

Fields #

NameDescription
Product Name
Product Version
ID UnicodeString
Detection Time
User UnicodeString
Destination UnicodeString
Process Name
ProductName UnicodeString
ProductVersion UnicodeString
DetectionTime UnicodeString
ProcessName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1125,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T14:15:45.4894125+00:00",
    "event_record_id": 6309,
    "correlation": {
      "ActivityID": "{BEE8253E-48BA-4F31-9D8C-72B08F80EAD3}"
    },
    "execution": {
      "process_id": 3292,
      "thread_id": 4288
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "ID": "",
    "Detection Time": "2026-05-30T14:15:45.488Z",
    "User": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "Destination": "https://smartscreenurlnetworkfilter.azurewebsites.net",
    "Process Name": "wsmprovhost.exe"
  },
  "message": "Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.\r\n \tDetection time: 2026-05-30T14:15:45.488Z\r\n \tUser: S-1-5-21-1006758700-2167138679-1475694448-1105\r\n \tDestination: https://smartscreenurlnetworkfilter.azurewebsites.net\r\n \tProcess Name: wsmprovhost.exe\r\n"
}

References #

Event ID 1126: Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (JSCU-NL)

Message #

Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.
 	Detection time: %4
 	User: %5
 	Destination: %6
 	Process Name: %7

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
ID UnicodeString
DetectionTime UnicodeString
User UnicodeString
Destination UnicodeString
ProcessName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 1126,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-19T17:19:26.482833+00:00",
    "event_record_id": 7670,
    "correlation": {
      "ActivityID": "33CB8B96-044D-499E-BBE3-20A2BDECC460"
    },
    "execution": {
      "process_id": 4548,
      "thread_id": 5964
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26060.3008",
    "ID": "",
    "Detection Time": "2026-07-19T17:19:26.482Z",
    "User": "S-1-5-21-1006758700-2167138679-1475694448-1105",
    "Destination": "https://smartscreentestratings2.net",
    "Process Name": "powershell.exe"
  },
  "message": ""
}

Example keys not documented in the fields table: Detection Time, Process Name, Product Name, Product Version

References #

Event ID 1127: Controlled Folder Access blocked ProcessName from making changes to memory.

#
Channel
Operational

Message #

Controlled Folder Access blocked %8 from making changes to memory.
 	Detection time: %5
 	User: %6
 	Path: %7
 	Process Name: %8
 	Security intelligence Version: %9
 	Engine Version: %10
 	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ID UnicodeString
DetectionTime UnicodeString
User UnicodeString
Path UnicodeString
ProcessName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1128: Controlled Folder Access would have blocked ProcessName from making changes to memory.

#
Channel
Operational

Message #

Controlled Folder Access would have blocked %8 from making changes to memory.
 	Detection time: %5
 	User: %6
 	Path: %7
 	Process Name: %8
 	Security intelligence Version: %9
 	Engine Version: %10
 	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ID UnicodeString
DetectionTime UnicodeString
User UnicodeString
Path UnicodeString
ProcessName UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1129: A user has allowed a blocked Microsoft Defender Exploit Guard operation.

#
Channel
Operational

Message #

A user has allowed a blocked Microsoft Defender Exploit Guard operation.
 	ID: %4
 	User: %5
 	Path: %6
 	Process Name: %7
 	Involved File: %8

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ID UnicodeString
User UnicodeString
Path UnicodeString
ProcessName UnicodeString
InvolvedFile UnicodeString

References #

Event ID 1130: {Product Name} blocked a behavior by {Source app}.

#
Channel
Operational

References #

Event ID 1131: ProductName has blocked an operation that your administrator doesn't allow.

#
Channel
Operational

Message #

%1 has blocked an operation that your administrator doesn't allow.
 For more information please contact your IT administrator.
 	ID: %4
 	State: %5
 	Timestamp: %6
 	Action: %7
 	Process: %8
 	Source: %9
 	Target: %10
 	User: %11
 %Security intelligence Version: %12
 	Engine Version: %13
 	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ID UnicodeString
State UnicodeString
Timestamp UnicodeString
Action UnicodeString
Process UnicodeString
Source UnicodeString
Target UnicodeString
User UnicodeString
SignatureVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1132: ProductName has audited an operation.

#
Channel
Operational

Message #

%1 has audited an operation.
 For more information please contact your IT administrator.
 	ID: %4
 	State: %5
 	Timestamp: %6
 	Action: %7
 	Process: %8
 	Source: %9
 	Target: %10
 	User: %11
 %Security intelligence Version: %12
 	Engine Version: %13
 	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ID UnicodeString
State UnicodeString
Timestamp UnicodeString
Action UnicodeString
Process UnicodeString
Source UnicodeString
Target UnicodeString
User UnicodeString
SignatureVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1133: ProductName has blocked an operation that your administrator doesn't allow.

#
Channel
Operational

Message #

%1 has blocked an operation that your administrator doesn't allow.
For more information please contact your IT administrator.
	Policy Version: %4
	Policy Rule ID: %5
	Enforcement Level: %6
	Timestamp: %8
	Action Type: %9
	Process: %10
	Source: %11
	Target: %12
	Session ID: %13
	User SID: %14
%Security intelligence Version: %15
	Engine Version: %16
	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
PolicyVersion UnicodeString
PolicyRuleId UnicodeString
EnforcementLevel UnicodeString
AuditReason UnicodeString
EventTimestamp UnicodeString
ActionType UnicodeString
Process UnicodeString
Source UnicodeString
Target UnicodeString
SessionId UnicodeString
UserSid UnicodeString
SignatureVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1134: ProductName has audited an operation.

#
Channel
Operational

Message #

%1 has audited an operation.
For more information please contact your IT administrator.
	Policy Version: %4
	Policy Rule ID: %5
	Enforcement Level: %6
	Audit Reason: %7
	Timestamp: %8
	Action Type: %9
	Process: %10
	Source: %11
	Target: %12
	Session ID: %13
	User SID: %14
%Security intelligence Version: %15
	Engine Version: %16
	Product Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
PolicyVersion UnicodeString
PolicyRuleId UnicodeString
EnforcementLevel UnicodeString
AuditReason UnicodeString
EventTimestamp UnicodeString
ActionType UnicodeString
Process UnicodeString
Source UnicodeString
Target UnicodeString
SessionId UnicodeString
UserSid UnicodeString
SignatureVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 1150: Endpoint Protection client is up and running in a healthy state.

#
Channel
Operational
Level
Informational

Message #

Endpoint Protection client is up and running in a healthy state.
 	Platform version: %2
 	Engine version: %4
 	Security intelligence version: %5

Fields #

NameDescription
Product Name
Platform version
Unused UnicodeString
Engine version
Security intelligence version
ProductName
Platformversion
Engineversion
Securityintelligenceversion

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1150,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T13:51:41.2952768+00:00",
    "event_record_id": 719,
    "correlation": {},
    "execution": {
      "process_id": 4284,
      "thread_id": 2924
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Platform version": "4.18.26050.15",
    "Unused": "",
    "Engine version": "1.1.26050.11",
    "Security intelligence version": "1.453.68.0"
  },
  "message": "Endpoint Protection client is up and running in a healthy state.\r\n \tPlatform version: 4.18.26050.15\r\n \tEngine version: 1.1.26050.11\r\n \tSecurity intelligence version: 1.453.68.0\r\n"
}

References #

Event ID 1151: Endpoint Protection client health report (time in UTC).

#
Channel
Operational
Level
Informational

Message #

Endpoint Protection client health report (time in UTC):
 	Platform version: %2
 	Engine version: %4
 	Network Realtime Inspection engine version: %5
 	Antivirus security intelligence version: %6
 	Antispyware security intelligence version: %7
 	Network Realtime Inspection security intelligence version: %8
 	RTP state: %9
 	OA state: %10
 	IOAV state: %11
 	BM state: %12
 	Antivirus security intelligence age: %13
 	Antispyware security intelligence age: %14
 	Last quick scan age: %15
 	Last full scan age: %16
 	Antivirus security intelligence creation time: %17
 	Antispyware security intelligence creation time: %18
 	Last quick scan start time: %19
 	Last quick scan end time: %20
 	Last quick scan source: %21
 	Last full scan start time: %22
 	Last full scan end time: %23
 	Last full scan source: %24
 	Product status: %25

Fields #

NameDescription
Product Name
Platform version
Unused UnicodeString
Engine version
NRI engine version
AV security intelligence version
AS security intelligence version
NRI security intelligence version
RTP state
OA state
IOAV state
BM state
Last AV security intelligence age
Last AS security intelligence age
Last quick scan age
Last full scan age
AV security intelligence creation time
AS security intelligence creation time
Last quick scan start time
Last quick scan end time
Last quick scan source
Last full scan start time
Last full scan end time
Last full scan source
Product status
Latest engine version
Engine up-to-date
Latest platform version
Platform up-to-date
ProductName
Platformversion
Engineversion
NRIengineversion
AVsecurityintelligenceversion
ASsecurityintelligenceversion
NRIsecurityintelligenceversion
RTPstate
OAstate
IOAVstate
BMstate
LastAVsecurityintelligenceage
LastASsecurityintelligenceage
Lastquickscanage
Lastfullscanage
AVsecurityintelligencecreationtime
ASsecurityintelligencecreationtime
Lastquickscanstarttime
Lastquickscanendtime
Lastquickscansource
Lastfullscanstarttime
Lastfullscanendtime
Lastfullscansource
Productstatus
Latestengineversion
Engineuptodate
Latestplatformversion
Platformuptodate

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 1151,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T13:51:41.2975836+00:00",
    "event_record_id": 720,
    "correlation": {},
    "execution": {
      "process_id": 4284,
      "thread_id": 2924
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Platform version": "4.18.26050.15",
    "Unused": "",
    "Engine version": "1.1.26050.11",
    "NRI engine version": "1.1.26050.11",
    "AV security intelligence version": "1.453.68.0",
    "AS security intelligence version": "1.453.68.0",
    "NRI security intelligence version": "1.453.68.0",
    "RTP state": "Enabled",
    "OA state": "Enabled",
    "IOAV state": "Enabled",
    "BM state": "Enabled",
    "Last AV security intelligence age": "0",
    "Last AS security intelligence age": "0",
    "Last quick scan age": "0",
    "Last full scan age": "4294967295",
    "AV security intelligence creation time": "2026-06-12T22:27:59Z",
    "AS security intelligence creation time": "2026-06-12T22:27:59Z",
    "Last quick scan start time": "2026-06-13T05:39:31Z",
    "Last quick scan end time": "2026-06-13T05:43:05Z",
    "Last quick scan source": "2",
    "Last full scan start time": "1601-01-01T00:00:00Z",
    "Last full scan end time": "1601-01-01T00:00:00Z",
    "Last full scan source": "0",
    "Product status": "0x00080000",
    "Latest engine version": "1.1.26050.11",
    "Engine up-to-date": "0",
    "Latest platform version": "4.18.26050.15",
    "Platform up-to-date": "1"
  },
  "message": "Endpoint Protection client health report (time in UTC):\r\n \tPlatform version: 4.18.26050.15\r\n \tEngine version: 1.1.26050.11\r\n \tNetwork Realtime Inspection engine version: 1.1.26050.11\r\n \tAntivirus security intelligence version: 1.453.68.0\r\n \tAntispyware security intelligence version: 1.453.68.0\r\n \tNetwork Realtime Inspection security intelligence version: 1.453.68.0\r\n \tRTP state: Enabled\r\n \tOA state: Enabled\r\n \tIOAV state: Enabled\r\n \tBM state: Enabled\r\n \tAntivirus security intelligence age: 0\r\n \tAntispyware security intelligence age: 0\r\n \tLast quick scan age: 0\r\n \tLast full scan age: 4294967295\r\n \tAntivirus security intelligence creation time: 2026-06-12T22:27:59Z\r\n \tAntispyware security intelligence creation time: 2026-06-12T22:27:59Z\r\n \tLast quick scan start time: 2026-06-13T05:39:31Z\r\n \tLast quick scan end time: 2026-06-13T05:43:05Z\r\n \tLast quick scan source: 2\r\n \tLast full scan start time: 1601-01-01T00:00:00Z\r\n \tLast full scan end time: 1601-01-01T00:00:00Z\r\n \tLast full scan source: 0\r\n \tProduct status: 0x00080000\r\n"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 1160: ProductName has detected potentially unwanted application(PUA).

#
Channel
Operational

Message #

%1 has detected potentially unwanted application(PUA).
 For more information please see the following:
%13
 	Name: %8
 	ID: %7
 	Severity: %10
 	Category: %12
 	Path: %22
 	Detection Origin: %24
 	Detection Type: %28
 	Detection Source: %18
 	User: %20
 	Process Name: %19
 	Security intelligence Version: %41
 	Engine Version: %42

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
DetectionID UnicodeString
DetectionTime UnicodeString
Unused UnicodeString
Unused2 UnicodeString
ThreatID UnicodeString
ThreatName UnicodeString
SeverityID UnicodeString
Known values
0
Unknown
1
Low
2
Moderate
4
High
5
Severe
SeverityName UnicodeString
CategoryID UnicodeString
CategoryName UnicodeString
FWLink UnicodeString
StatusCode UnicodeStringNTSTATUS reference
StatusDescription UnicodeString
State UnicodeString
SourceID UnicodeString
Known values
0
Unknown
1
User - user initiated scan
2
System - system initiated scan
3
Real-time - real-time protection component
4
IOAV - IE Downloads and Outlook Express Attachments
5
NIS - Network Inspection System
7
ELAM - Early Launch Antimalware (boot sequence)
8
Local attestation
9
Remote attestation
SourceName UnicodeString
ProcessName UnicodeString
DetectionUser UnicodeString
Unused3 UnicodeString
Path UnicodeString
OriginID UnicodeString
Known values
0
Unknown
1
Local machine
2
Network share
3
Internet
4
Incoming traffic
5
Outgoing traffic
OriginName UnicodeString
ExecutionID UnicodeString
ExecutionName UnicodeString
TypeID UnicodeString
TypeName UnicodeString
PreExecutionStatus UnicodeString
ActionID UnicodeString
Known values
1
Clean - the resource was cleaned
2
Quarantine - the resource was quarantined
3
Remove - the resource was deleted
6
Allow - the resource was allowed to execute/exist
8
User defined - action determined by user policy
9
NoAction - no action taken (detection only; matches MSFT_MpPreference value 9 NoAction)
10
Block - the resource was blocked from executing
ActionName UnicodeString
Unused4 UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused5 UnicodeString
PostCleanStatus UnicodeString
AdditionalActionsID UnicodeString
AdditionalActionsString UnicodeString
RemediationUser UnicodeString
Unused6 UnicodeString
SecurityintelligenceVersion UnicodeString
EngineVersion UnicodeString

References #

Event ID 2000: Product Name security intelligence version updated.

#
Channel
Operational
Level
Informational

Message #

%1 security intelligence version updated.
 	Current security intelligence Version: %3
 	Previous security intelligence Version: %4
 	Security intelligence Type: %12
 	Update Type: %14
 	User: %8\%9
 	Current Engine Version: %15
 	Previous Engine Version: %16

Fields #

NameDescription
Product Name
Product Version
Current security intelligence Version
Previous security intelligence Version
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
Security intelligence Type Index
Security intelligence Type
Update Type Index
Update Type
Current Engine Version
Previous Engine Version
ProductName
ProductVersion
CurrentsecurityintelligenceVersion
PrevioussecurityintelligenceVersion
SecurityintelligenceTypeIndex
SecurityintelligenceType
UpdateTypeIndex
UpdateType
CurrentEngineVersion
PreviousEngineVersion

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 2000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:50:53.3765037+00:00",
    "event_record_id": 686,
    "correlation": {},
    "execution": {
      "process_id": 3912,
      "thread_id": 3464
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Current security intelligence Version": "1.453.68.0",
    "Previous security intelligence Version": "1.451.171.0",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Security intelligence Type Index": "2",
    "Security intelligence Type": "AntiSpyware",
    "Update Type Index": "1",
    "Update Type": "Full",
    "Current Engine Version": "1.1.26050.11",
    "Previous Engine Version": "1.1.26040.8"
  },
  "message": "Microsoft Defender Antivirus security intelligence version updated.\r\n \tCurrent security intelligence Version: 1.453.68.0\r\n \tPrevious security intelligence Version: 1.451.171.0\r\n \tSecurity intelligence Type: AntiSpyware\r\n \tUpdate Type: Full\r\n \tUser: NT AUTHORITY\\SYSTEM\r\n \tCurrent Engine Version: 1.1.26050.11\r\n \tPrevious Engine Version: 1.1.26040.8"
}

References #

Event ID 2001: Product Name has encountered an error trying to update security intelligence.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Olaf Hartong)

Message #

%1 has encountered an error trying to update security intelligence.
 	New security intelligence Version: %3
 	Previous security intelligence Version: %4
 	Update Source: %6
 	Security intelligence Type: %12
 	Update Type: %14
 	User: %8\%9
 	Current Engine Version: %15
 	Previous Engine Version: %16
 	Error code: %17
 	Error description: %18

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
CurrentsecurityintelligenceVersion UnicodeString
PrevioussecurityintelligenceVersion UnicodeString
UpdateSourceIndex UnicodeString
UpdateSource UnicodeString
Unused UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
SecurityintelligenceTypeIndex UnicodeString
SecurityintelligenceType UnicodeString
UpdateTypeIndex UnicodeString
UpdateType UnicodeString
CurrentEngineVersion UnicodeString
PreviousEngineVersion UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
UpdateStateIndex UnicodeString
UpdateState UnicodeString
SourcePath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 2001,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-09T01:17:06.846703+00:00",
    "event_record_id": 1315,
    "correlation": {
      "ActivityID": "4BE4BD99-4F61-4990-9CE4-215B5E5A9104"
    },
    "execution": {
      "process_id": 3728,
      "thread_id": 5300
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26010.5",
    "Current security intelligence Version": "",
    "Previous security intelligence Version": "1.445.426.0",
    "Update Source Index": "7",
    "Update Source": "Microsoft Update Server",
    "Unused": "",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Security intelligence Type Index": "1",
    "Security intelligence Type": "AntiVirus",
    "Update Type Index": "1",
    "Update Type": "Full",
    "Current Engine Version": "",
    "Previous Engine Version": "1.1.26010.1",
    "Error Code": "0x8007045b",
    "Error Description": "A system shutdown is in progress. ",
    "Update State Index": "1",
    "Update State": "Search",
    "Source Path": "Default URL"
  },
  "message": ""
}

Example keys not documented in the fields table: Current Engine Version, Current security intelligence Version, Error Code, Error Description, Previous Engine Version, Previous security intelligence Version, Product Name, Product Version, Security intelligence Type, Security intelligence Type Index, Source Path, Update Source, Update Source Index, Update State, Update State Index, Update Type, Update Type Index

References #

Event ID 2002: Product Name engine version has been updated.

#
Channel
Operational
Level
Informational

Message #

%1 engine version has been updated.
 	Current Engine Version: %3
 	Previous Engine Version: %4
 	User: %8\%9

Fields #

NameDescription
Product Name
Product Version
Current Engine Version
Previous Engine Version
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
Unused4 UnicodeString
Unused5 UnicodeString
Feature Index
Feature Name
ProductName
ProductVersion
CurrentEngineVersion
PreviousEngineVersion
FeatureIndex
FeatureName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 2002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:50:53.3754720+00:00",
    "event_record_id": 684,
    "correlation": {},
    "execution": {
      "process_id": 3912,
      "thread_id": 3464
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Current Engine Version": "1.1.26050.11",
    "Previous Engine Version": "1.1.26040.8",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Domain": "NT AUTHORITY",
    "User": "SYSTEM",
    "SID": "S-1-5-18",
    "Unused4": "",
    "Unused5": "",
    "Feature Index": "0",
    "Feature Name": "Antimalware"
  },
  "message": "Microsoft Defender Antivirus engine version has been updated.\r\n \tCurrent Engine Version: 1.1.26050.11\r\n \tPrevious Engine Version: 1.1.26040.8\r\n \tUser: NT AUTHORITY\\SYSTEM"
}

References #

Event ID 2003: ProductName has encountered an error trying to update the engine.

#
Channel
Operational
Collection Priority
Recommended (NSA, others)

Message #

%1 has encountered an error trying to update the engine.
 	New Engine Version: %3
 	Previous Engine Version: %4
 	User: %8\%9
 	Error Code: %11
 	Error description: %12

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
CurrentEngineVersion UnicodeString
PreviousEngineVersion UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
UpdateStateIndex UnicodeString
UpdateState UnicodeString

References #

Event ID 2004: ProductName has encountered an error trying to update security intelligence and will attempt to revert to a previous version.

#
Channel
Operational
Collection Priority
Recommended (NSA, others)

Message #

%1 has encountered an error trying to update security intelligence and will attempt to revert to a previous version.
 	Security intelligence Attempted: %4
 	Error Code: %5
 	Error description: %6
 	Security intelligence Version: %9
 	Engine Version: %10

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
SecurityintelligenceAttemptedIndex UnicodeString
SecurityintelligenceAttempted UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Loadingsecurityintelligenceversion UnicodeString
Loadingengineversion UnicodeString

References #

Event ID 2005: ProductName could not load antimalware engine because current platform version is not supported.

#
Channel
Operational

Description

ProductName could not load antimalware engine because current platform version is not supported. ProductName will revert back to the last known-good engine and a platform update will be attempted.

Message #

%1 could not load antimalware engine because current platform version is not supported. %1 will revert back to the last known-good engine and a platform update will be attempted.
 	Current Platform Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

References #

Event ID 2006: ProductName has encountered an error trying to update the platform.

#
Channel
Operational

Message #

%1 has encountered an error trying to update the platform.
 	Current Platform Version: %2
 	Error code: %4
 	Error description: %5

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString

References #

Event ID 2007: ProductName will soon require a newer platform version to support future versions of the antimalware engine.

#
Channel
Operational

Description

ProductName will soon require a newer platform version to support future versions of the antimalware engine. Download the latest ProductName platform to maintain the best level of protection available.

Message #

%1 will soon require a newer platform version to support future versions of the antimalware engine. Download the latest %1 platform to maintain the best level of protection available.
 	Current Platform Version: %2

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

References #

Event ID 2008: ProductName platform update update to NewPlatformVersion is paused due to system activity.

#
Channel
Operational

Description

ProductName platform update update to NewPlatformVersion is paused due to system activity. For more details see the latest MpLog*.log entry under ProgramData.

Message #

%1 platform update update to %4 is paused due to system activity. For more details see the latest MpLog*.log entry under ProgramData.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
NewPlatformVersion UnicodeString

References #

Event ID 2009: ProductName platform update to NewPlatformVersion has resumed.

#
Channel
Operational

Message #

%1 platform update to %4 has resumed.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
NewPlatformVersion UnicodeString

References #

Event ID 2010: Product Name used cloud protection to get additional security intelligence.

#
Channel
Operational
Level
Informational

Message #

%1 used cloud protection to get additional security intelligence.
 	Current security intelligence Version: %3
 	Security intelligence Type: %12
 	User: %8\%9
 	Current Engine Version: %15
 	Cloud protection intelligence Type: %23
 	Persistence Path: %24
 	Cloud protection intelligence Version: %25
 	Cloud protection intelligence Compilation Timestamp: %26
 	Persistence Limit Type: %28
 	Persistence Limit: %29

Fields #

NameDescription
Product Name
Product Version
Current security intelligence Version
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
Security intelligence Type Index
Security intelligence Type
Unused5 UnicodeString
Unused6 UnicodeString
Current Engine Version
Unused7 UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
Unused11 UnicodeString
Unused12 UnicodeString
Cloud protection intelligence Type Index
Cloud protection intelligence Type
Persistence Path
Cloud protection intelligence Version
Cloud protection intelligence Compilation Timestamp
Persistence Limit Type Index
Persistence Limit Type
Persistence Limit Value
ProductName
ProductVersion
CurrentsecurityintelligenceVersion
SecurityintelligenceTypeIndex
SecurityintelligenceType
CurrentEngineVersion
CloudprotectionintelligenceTypeIndex
CloudprotectionintelligenceType
PersistencePath
CloudprotectionintelligenceVersion
CloudprotectionintelligenceCompilationTimestamp
PersistenceLimitTypeIndex
PersistenceLimitType
PersistenceLimitValue

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 2010,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-28T12:08:47.2710212+00:00",
    "event_record_id": 339,
    "correlation": {},
    "execution": {
      "process_id": 3524,
      "thread_id": 4460
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Current security intelligence Version": "1.451.146.0",
    "Unused": "",
    "Unused2": "",
    "Unused3": "",
    "Unused4": "",
    "Domain": "",
    "User": "",
    "SID": "",
    "Security intelligence Type Index": "0",
    "Security intelligence Type": "",
    "Unused5": "",
    "Unused6": "",
    "Current Engine Version": "1.1.26040.8",
    "Unused7": "",
    "Unused8": "",
    "Unused9": "",
    "Unused10": "",
    "Unused11": "",
    "Unused12": "",
    "Cloud protection intelligence Type Index": "1",
    "Cloud protection intelligence Type": "Security intelligence update",
    "Persistence Path": "C:\\ProgramData\\Microsoft\\Windows Defender\\Scans\\RtSigs\\data\\16d35a2b712b574f78fd5dde93e1caea89414ad1",
    "Cloud protection intelligence Version": "0.0.0.0",
    "Cloud protection intelligence Compilation Timestamp": "5/28/2026 7:08:47 PM",
    "Persistence Limit Type Index": "2",
    "Persistence Limit Type": "Duration",
    "Persistence Limit Value": "288000000"
  },
  "message": "Microsoft Defender Antivirus used cloud protection to get additional security intelligence.\r\n \tCurrent security intelligence Version: 1.451.146.0\r\n \tSecurity intelligence Type: \r\n \tUser: \\\r\n \tCurrent Engine Version: 1.1.26040.8\r\n \tCloud protection intelligence Type: Security intelligence update\r\n \tPersistence Path: C:\\ProgramData\\Microsoft\\Windows Defender\\Scans\\RtSigs\\data\\16d35a2b712b574f78fd5dde93e1caea89414ad1\r\n \tCloud protection intelligence Version: 0.0.0.0\r\n \tCloud protection intelligence Compilation Timestamp: 5/28/2026 7:08:47 PM\r\n \tPersistence Limit Type: Duration\r\n \tPersistence Limit: 288000000"
}

References #

Event ID 2011: ProductName used cloud protection to discard obsolete security intelligence updates.

#
Channel
Operational

Message #

%1 used cloud protection to discard obsolete security intelligence updates.
 	Current security intelligence Version: %3
 	Security intelligence Type: %12
 	Current Engine Version: %15
 	Cloud protection intelligence Type: %23
 	Persistence Path: %24
 	Cloud protection intelligence Version: %25
 	Cloud protection intelligence Compilation Timestamp: %26
 	Removal Reason: %31
 	Persistence Limit Type: %28
 	Persistence Limit: %29

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
CurrentsecurityintelligenceVersion UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
SecurityintelligenceTypeIndex UnicodeString
SecurityintelligenceType UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
CurrentEngineVersion UnicodeString
Unused7 UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
Unused11 UnicodeString
Unused12 UnicodeString
CloudprotectionintelligenceTypeIndex UnicodeString
CloudprotectionintelligenceType UnicodeString
PersistencePath UnicodeString
CloudprotectionintelligenceVersion UnicodeString
CloudprotectionintelligenceCompilationTimestamp UnicodeString
PersistenceLimitTypeIndex UnicodeString
PersistenceLimitType UnicodeString
PersistenceLimitValue UnicodeString
RemovalReasonIndex UnicodeString
RemovalReasonValue UnicodeString

References #

Event ID 2012: ProductName has encountered an error trying to use cloud protection.

#
Channel
Operational

Message #

%1 has encountered an error trying to use cloud protection.
 	Current security intelligence Version: %3
 	Security intelligence Type: %12
 	User: %8\%9
 	Current Engine Version: %15
 	Error code: %17
 	Error description: %18 	Cloud protection intelligence Type: %23
 	Persistence Path: %24
 	Cloud protection intelligence Version: %25
 	Cloud protection intelligence Compilation Timestamp: %26
 	Persistence Limit Type: %28
 	Persistence Limit: %29

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
CurrentsecurityintelligenceVersion UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
SecurityintelligenceTypeIndex UnicodeString
SecurityintelligenceType UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
CurrentEngineVersion UnicodeString
Unused7 UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
Unused8 UnicodeString
Unused9 UnicodeString
Unused10 UnicodeString
CloudprotectionintelligenceTypeIndex UnicodeString
CloudprotectionintelligenceType UnicodeString
PersistencePath UnicodeString
CloudprotectionintelligenceVersion UnicodeString
CloudprotectionintelligenceCompilationTimestamp UnicodeString
PersistenceLimitTypeIndex UnicodeString
PersistenceLimitType UnicodeString
PersistenceLimitValue UnicodeString

References #

Event ID 2013: ProductName discarded all cloud protection intelligence.

#
Channel
Operational

Message #

%1 discarded all cloud protection intelligence.
 	User: %8\%9
 	Current Engine Version: %15

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
CurrentsecurityintelligenceVersion UnicodeString
Unused UnicodeString
Unused2 UnicodeString
Unused3 UnicodeString
Unused4 UnicodeString
Domain UnicodeString
User UnicodeString
SID UnicodeString
SecurityintelligenceTypeIndex UnicodeString
SecurityintelligenceType UnicodeString
Unused5 UnicodeString
Unused6 UnicodeString
CurrentEngineVersion UnicodeString

References #

Event ID 2014: Product Name platform update to Product Version has succeeded.

#
Channel
Operational
Level
Informational

Message #

%1 platform update to %2 has succeeded.

Fields #

NameDescription
Product Name
Product Version
ProductName
ProductVersion

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 2014,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:51:26.5086726+00:00",
    "event_record_id": 694,
    "correlation": {},
    "execution": {
      "process_id": 4284,
      "thread_id": 4512
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26050.15"
  },
  "message": "Microsoft Defender Antivirus platform update to 4.18.26050.15 has succeeded.\r\n"
}

References #

Event ID 2020: {Product Name} downloaded a clean file.

#
Channel
Operational

Description

{Product Name} downloaded a clean file. Filename: {Filename} Current Signature Version: {Current Signature Version} Current Engine Version: {Current Engine Version}.

Message #

{Product Name} downloaded a clean file. 	Filename: {Filename} 	Current Signature Version: {Current Signature Version} 	Current Engine Version: {Current Engine Version}

Fields #

NameDescription
Filename

References #

Event ID 2021: {Product Name} has encountered an error trying to download a clean file.

#
Channel
Operational

Message #

{Product Name} has encountered an error trying to download a clean file. 	Filename: {Filename} 	Current Signature Version: {Current Signature Version} 	Current Engine Version: {Current Engine Version} 	Error code: {Error Code} 	Error description: {Error Description}

Fields #

NameDescription
Filename

References #

Event ID 2030: ProductName downloaded and configured Microsoft Defender Antivirus (offline scan) to run on the next reboot.

#
Channel
Operational

Message #

%1 downloaded and configured Microsoft Defender Antivirus (offline scan) to run on the next reboot.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

References #

Event ID 2031: ProductName has encountered an error trying to download and configure Microsoft Defender Antivirus (offline scan).

#
Channel
Operational

Message #

%1 has encountered an error trying to download and configure Microsoft Defender Antivirus (offline scan).
	Error code: %4
	Error description: %5

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Unused UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString

References #

Event ID 2040: The support for your operating system will expire shortly.

#
Channel
Operational

Description

The support for your operating system will expire shortly. Running ProductName on an out of support operating system is not an adequate solution to protect against threats.

Message #

The support for your operating system will expire shortly. Running %1 on an out of support operating system is not an adequate solution to protect against threats.

Fields #

NameDescription
ProductName UnicodeString
Unused UnicodeString
Unused2 UnicodeString

References #

Event ID 2041: The support for your operating system has expired.

#
Channel
Operational

Description

The support for your operating system has expired. Running ProductName on an out of support operating system is not an adequate solution to protect against threats.

Message #

The support for your operating system has expired. Running %1 on an out of support operating system is not an adequate solution to protect against threats.

Fields #

NameDescription
ProductName UnicodeString
Unused UnicodeString
Unused2 UnicodeString

References #

Event ID 2042: The support for your operating system has expired.

#
Channel
Operational

Description

The support for your operating system has expired. ProductName is no longer supported on your operating system, has stopped functioning, and is not protecting against malware threats.

Message #

The support for your operating system has expired. %1 is no longer supported on your operating system, has stopped functioning, and is not protecting against malware threats.

Fields #

NameDescription
ProductName UnicodeString
Unused UnicodeString
Unused2 UnicodeString

References #

Event ID 2050: Product Name has uploaded a file for further analysis.

#
Channel
Operational
Level
Informational

Message #

%1 has uploaded a file for further analysis.
 	Filename: %3
 	Sha256: %4

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Filename UnicodeString
Sha256 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 2050,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-02-12T18:54:35.585634+00:00",
    "event_record_id": 750,
    "correlation": {
      "ActivityID": "BE515C10-E001-43C7-997D-42CF5BAA18A7"
    },
    "execution": {
      "process_id": 8580,
      "thread_id": 4832
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26010.5",
    "Filename": "C:\\Users\\domainuser\\Downloads\\ScreenConnect.ClientSetup.exe",
    "Sha256": "981233ccb88f5d6dcb9d7856c364c1d377153564202bba6935f97da5d2f3d316"
  },
  "message": ""
}

Example keys not documented in the fields table: Product Name, Product Version

References #

Event ID 2051: ProductName has encountered an error trying to upload a suspicious file for further analysis.

#
Channel
Operational

Message #

%1 has encountered an error trying to upload a suspicious file for further analysis.
 	Filename: %3
 	Sha256: %4
 	Current security intelligence Version: %5
 	Current Engine Version: %6
 	Error code: %7

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Filename UnicodeString
Sha256 UnicodeString
CurrentsecurityintelligenceVersion UnicodeString
CurrentEngineVersion UnicodeString
ErrorCode UnicodeString

References #

Event ID 3000: {Product Name} Real-Time Protection agents have started.

#
Channel
Operational

Description

{Product Name} Real-Time Protection agents have started. User: {Domain}\{User}.

Message #

{Product Name} Real-Time Protection agents have started. 	User: {Domain}\{User}

Fields #

NameDescription
Domain
User

References #

Event ID 3001: {Product Name}Real-Time Protection agents have stopped.

#
Channel
Operational

Description

{Product Name}Real-Time Protection agents have stopped. User: {Domain}\{User}.

Message #

{Product Name}Real-Time Protection agents have stopped. 	User: {Domain}\{User}

Fields #

NameDescription
Domain
User

References #

Event ID 3002: ProductName Real-Time Protection feature has encountered an error and failed.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Olaf Hartong)

Message #

%1 Real-Time Protection feature has encountered an error and failed.
 	Feature: %3
 	Error Code: %5
 	Error description: %6
 	Reason: %4

Fields #

NameDescriptionRules
Product Name
Product Version
Feature Name
Reason UnicodeString2 detection rules
Error Code
Error Description
Feature ID
ProductName UnicodeString
ProductVersion UnicodeString
FeatureName UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString
FeatureID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78",
    "event_source_name": "",
    "event_id": 3002,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-18T01:13:18.9508995+00:00",
    "event_record_id": 7585,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 11220,
      "thread_id": 9152
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26060.3008",
    "Feature Name": "On Access",
    "Reason": "Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.",
    "Error Code": "0x8007051a",
    "Error Description": "Indicates two revision levels are incompatible. ",
    "Feature ID": "3"
  },
  "message": "Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.\r\n \tFeature: On Access\r\n \tError Code: 0x8007051a\r\n \tError description: Indicates two revision levels are incompatible. \r\n \tReason: Antimalware security intelligence has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem."
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 3003: {Product Name} Real-Time Protection checkpoint has encountered an error and failed to start.

#
Channel
Operational

Message #

{Product Name} Real-Time Protection checkpoint has encountered an error and failed to start. 	User: {Domain}\{User} 	Checkpoint ID: {Checkpoint} 	Error Code: {Error Code} 	Error description: {Error Description}

Fields #

NameDescription
Domain
User
Checkpoint

References #

Event ID 3004: {Product Name} Real-Time Protection agent has detected changes.

#
Channel
Operational

Message #

{Product Name} Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer.  Allow changes only if you trust the program or the software publisher. {Product Name} can't undo changes that you allow. For more information please see the following:{Product Name}5 	Scan ID: {Scan ID} 	User: {Domain}\{User} 	Name: {Product Name}1 	ID: {Product Name}2 	Severity ID: {Product Name}3 	Category ID: {Product Name}4 	Path Found: {Product Name}6 	Alert Type: {Product Name}8 	Detection Type: {Product Version}2

Fields #

NameDescription
Domain
User

References #

Event ID 3005: {Product Name} Real-Time Protection agent has taken action to protect this machine from spyware or other potentially unwanted software.

#
Channel
Operational

Message #

{Product Name} Real-Time Protection agent has taken action to protect this machine from spyware or other potentially unwanted software. For more information please see the following:{Product Name}5 	Scan ID: {Scan ID} 	User: {Domain}\{User} 	Name: {Product Name}1 	ID: {Product Name}2 	Severity ID: {Product Name}3 	Category ID: {Product Name}4 	Alert Type: {Product Name}8 	Action: {Product Version}0

Fields #

NameDescription
Domain
User

References #

Event ID 3006: {Product Name} Real-Time Protection agent has encountered an error when taking action on spyware or other potentially unwanted software.

#
Channel
Operational

Message #

{Product Name} Real-Time Protection agent has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following:{Product Name}5 	Scan ID: {Scan ID} 	User: {Domain}\{User} 	Name: {Product Name}1 	ID: {Product Name}2 	Severity ID: {Product Name}3 	Category ID: {Product Name}4 	Path: {Product Name}6 	Alert Type: {Product Name}8 	Action: {Product Version}0 	Error Code: {Product Version}1 	Error description: {Product Version}2

Fields #

NameDescription
Domain
User

References #

Event ID 3007: ProductName Real-time Protection feature has restarted.

#
Channel
Operational

Description

ProductName Real-time Protection feature has restarted. It is recommended that you run a full system scan to detect any items that may have been missed while this agent was down.

Message #

%1 Real-time Protection feature has restarted. It is recommended that you run a full system scan to detect any items that may have been missed while this agent was down.
 	Feature: %3
 	Reason: %4

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
FeatureName UnicodeString
Reason UnicodeString
Unused UnicodeString
Unused2 UnicodeString
FeatureID UnicodeString

References #

Event ID 4000: {Product Name} AV OnAccess Filter has detected spyware or other potentially unwanted software.

#
Channel
Operational

Message #

{Product Name} AV OnAccess Filter has detected spyware or other potentially unwanted software. For more information please see the following:{Product Name}5 	Scan ID: {param2} 	User: {param7}\{param8} 	Name: {Product Name}1 	ID: {Product Name}2 	Severity ID: {Product Name}3 	Category ID: {Product Name}4 	Path Found: {Product Name}6 	Local Copy Path: {Product Name}7 	Process Name: {Product Name}8 	Detection Type: {param1}2

Fields #

NameDescription
param2
param7
param8
param1

References #

Event ID 4002: {param1} AV OnAccess Filter has taken action to protect this machine from detected spyware or other potentially unwanted software.

#
Channel
Operational

Message #

{param1} AV OnAccess Filter has taken action to protect this machine from detected spyware or other potentially unwanted software. For more information please see the following:{param1}5 	Scan ID: {param3} 	User: {param8}\{param9} 	Name: {param1}1 	ID: {param1}2 	Severity ID: {param1}3 	Category ID: {param1}4 	Action: {param2}0

Fields #

NameDescription
param1
param3
param8
param9
param2

References #

Event ID 4003: {param1} AV OnAccess Filter has encountered an error when taking action on detected spyware or other potentially unwanted software.

#
Channel
Operational

Message #

{param1} AV OnAccess Filter has encountered an error when taking action on detected spyware or other potentially unwanted software. For more information please see the following:{param1}5 	Scan ID: {param3} 	User: {param8}\{param9} 	Name: {param1}1 	ID: {param1}2 	Severity ID: {param1}3 	Category ID: {param1}4 	Path: {param1}6 	Action: {param2}0 	Error Code: {param2}1 	Error Description: {param2}2

Fields #

NameDescription
param1
param3
param8
param9
param2

References #

Event ID 5000: ProductName Real-time Protection scanning for malware and other potentially unwanted software was enabled.

#
Channel
Operational
Level
Informational

Message #

%1 Real-time Protection scanning for malware and other potentially unwanted software was enabled.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "event_id": 5000,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-27T23:00:19.5556575+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-Windows Defender"
  },
  "event_data": {
    "Product Version": "4.18.26030.3011",
    "Product Name": "Microsoft Defender Antivirus"
  }
}

Example keys not documented in the fields table: Product Name, Product Version

References #

Event ID 5001: Product Name Real-time Protection scanning for malware and other potentially unwanted software was disabled.

#
Channel
Operational
Level
Informational

Message #

%1 Real-time Protection scanning for malware and other potentially unwanted software was disabled.

Fields #

NameDescription
ProductName
ProductVersion

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 5001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T00:11:26.945147+00:00",
    "event_record_id": 150,
    "correlation": {},
    "execution": {
      "process_id": 3332,
      "thread_id": 9444
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.23090.2008"
  },
  "message": ""
}

Example keys not documented in the fields table: Product Name, Product Version

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

  • Windows Defender Real-time Protection Disabled source high: Detects disabling of Windows Defender Real-time Protection. As this event doesn't contain a lot of information on who initiated this action you might want to reduce it to a "medium" level if this occurs too many times in your environmentT1685

References #

Event ID 5002: {param1} OnAccess scanning for viruses was enabled.

#
Channel
Operational

Fields #

NameDescription
param1

References #

Event ID 5003: {param1} OnAccess scanning for viruses was disabled.

#
Channel
Operational

Fields #

NameDescription
param1

References #

Event ID 5004: Product Name Real-time Protection feature configuration has changed.

#
Channel
Operational
Level
Informational

Message #

%1 Real-time Protection feature configuration has changed.
 	Feature: %3
 	Configuration: %4

Fields #

NameDescription
Product Name
Product Version
Feature Name
Configuration UnicodeString
Unused UnicodeString
Feature ID
ProductName
ProductVersion
FeatureName
FeatureID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 5004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:51:16.3201393+00:00",
    "event_record_id": 689,
    "correlation": {},
    "execution": {
      "process_id": 3912,
      "thread_id": 4984
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26040.7",
    "Feature Name": "Network Inspection System",
    "Configuration": "1",
    "Unused": "",
    "Feature ID": "9"
  },
  "message": "Microsoft Defender Antivirus Real-time Protection feature configuration has changed.\r\n \tFeature: Network Inspection System\r\n \tConfiguration: 1"
}

References #

Event ID 5005: {Product Name} Real-time Protection checkpoint configuration has changed.

#
Channel
Operational

Description

{Product Name} Real-time Protection checkpoint configuration has changed. Checkpoint: {Checkpoint} Configuration: {Configuration}.

Message #

{Product Name} Real-time Protection checkpoint configuration has changed. 	Checkpoint: {Checkpoint} 	Configuration: {Configuration}

Fields #

NameDescription
Checkpoint
Configuration

References #

Event ID 5006: {param1} OnAccess filter seems to be a unloaded - OnAccess scanning is disabled - Please restart the service.

#
Channel
Operational

Fields #

NameDescription
param1

References #

Event ID 5007: Product Name Configuration has changed.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (JSCU-NL)

Description

Product Name Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.

Message #

%1 Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.
 	Old value: %3
 	New value: %4

Fields #

NameDescriptionRules
Product Name
Product Version
Old Value
New Value1 detection rule
ProductName
ProductVersion
OldValue1 detection rule
NewValue13 detection rules

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}",
    "event_source_name": "",
    "event_id": 5007,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:51:41.6499897+00:00",
    "event_record_id": 704,
    "correlation": {},
    "execution": {
      "process_id": 4284,
      "thread_id": 4508
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26050.15",
    "Old Value": "HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Features\\Controls\\278 = 0x0",
    "New Value": ""
  },
  "message": "Microsoft Defender Antivirus Configuration has changed. If this is an unexpected event you should review the settings as this may be the result of malware.\r\n \tOld value: HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Features\\Controls\\278 = 0x0\r\n \tNew value: "
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Detailscontains\appdata\local\temp\1 rulesigma
Detailscontains\desktop\1 rulesigma
Detailscontains\perflogs\1 rulesigma
Detailscontains\users\public\1 rulesigma
Detailscontains\windows\temp\1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Splunk # view in coverage

  • Windows Defender ASR Registry Modification source: The following analytic detects modifications to Windows Defender Attack Surface Reduction (ASR) registry settings. It leverages Windows Defender Operational logs, specifically EventCode 5007, to identify changes in ASR rules. This activity…T1112
  • Windows Defender ASR Rule Disabled source: The following analytic identifies when a Windows Defender ASR rule disabled events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines.…T1112

References #

Event ID 5008: ProductName engine has been terminated due to an unexpected error.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Olaf Hartong)

Message #

%1 engine has been terminated due to an unexpected error.
 	Failure Type: %5
 	Exception code: %6
 	Resource: %3
 	Engine Code: %7

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
Resource UnicodeString
FailureTypeIndex UnicodeString
FailureType UnicodeString
ExceptionCode UnicodeString
Product Name
Product Version
Failure Type Index
Failure Type
Exception Code
Engine Code

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}",
    "event_source_name": "",
    "event_id": "5008",
    "version": "0",
    "level": "2",
    "task": "0",
    "opcode": "0",
    "keywords": 9223372036854775808,
    "time_created": "2026-06-09T15:55:23.8691138+00:00",
    "event_record_id": "7269",
    "correlation": {},
    "execution": {
      "process_id": "14036",
      "thread_id": "9348"
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26050.15",
    "Resource": "Unknown",
    "Failure Type Index": "4",
    "Failure Type": "Unexpected Crash",
    "Exception Code": "0xc0000420",
    "Engine Code": "1627863"
  },
  "message": ""
}

References #

Event ID 5009: ProductName scanning for spyware and other potentially unwanted software has been enabled.

#
Channel
Operational

Message #

%1 scanning for spyware and other potentially unwanted software has been enabled.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

References #

Event ID 5010: ProductName scanning for spyware and other potentially unwanted software is disabled.

#
Channel
Operational

Message #

%1 scanning for spyware and other potentially unwanted software is disabled.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 5011: ProductName scanning for viruses has been enabled.

#
Channel
Operational

Message #

%1 scanning for viruses has been enabled.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

References #

Event ID 5012: ProductName scanning for viruses is disabled.

#
Channel
Operational

Message #

%1 scanning for viruses is disabled.

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 5013: Tamper Protection Changed Type a change to Product Name.

#
Channel
Operational
Level
Informational

Message #

Tamper Protection %3 a change to %1.
 	Value: %4

Fields #

NameDescriptionRules
ProductName UnicodeString
ProductVersion UnicodeString
ChangedType UnicodeString
Value UnicodeString8 detection rules

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 5013,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-02-10T04:30:16.233011+00:00",
    "event_record_id": 264,
    "correlation": {},
    "execution": {
      "process_id": 8580,
      "thread_id": 3380
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26010.5",
    "Changed Type": "Ignored",
    "Value": "HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\SPYNET\\SpyNetReporting = 0x2"
  },
  "message": ""
}

Example keys not documented in the fields table: Changed Type, Product Name, Product Version

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 5014: ProductName Resource Monitor: Memory consumption exceeded its limit.

#
Channel
Operational

Message #

%1 Resource Monitor: Memory consumption exceeded its limit.
 	Hit count: %3
 	Current Threshold: %4

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
HitCount UnicodeString
Threshold UnicodeString

References #

Event ID 5015: ProductName Resource Monitor: CPU utilization exceeded its limit.

#
Channel
Operational

Message #

%1 Resource Monitor: CPU utilization exceeded its limit.
 	Hit count: %3
 	Current Threshold: %4

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
HitCount UnicodeString
Threshold UnicodeString

References #

Event ID 5016: ProductName service seemed to be hung during shutdown.

#
Channel
Operational
Level
Error

Message #

%1 service seemed to be hung during shutdown.
 	Timout (seconds): %3
 	Component: %4
 	Self-terminated: %5

Fields #

NameDescription
Product Name
Product Version
Timeout UnicodeString
Component UnicodeString
Crashed UnicodeString
ProductName UnicodeString
ProductVersion UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78",
    "event_source_name": "",
    "event_id": 5016,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-07-17T07:15:40.7082162+00:00",
    "event_record_id": 7580,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 4124,
      "thread_id": 7176
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26050.15",
    "Timeout": "120",
    "Component": "CleanupMpServiceRpc",
    "Crashed": "0"
  },
  "message": "Microsoft Defender Antivirus service seemed to be hung during shutdown.\r\n \tTimout (seconds):  120\r\n \tComponent:  CleanupMpServiceRpc\r\n \tSelf-terminated:  0"
}

References #

Event ID 5017: Product Name service feature has encountered an error and failed.

#
Channel
Operational
Level
Informational

Message #

%1 service feature has encountered an error and failed.
 	Feature: %3
  	Failure Reason: %5
 	Recommended Mitigation: %6
 	Error Code: %7
 	Error description: %8

Fields #

NameDescription
ProductName UnicodeString
ProductVersion UnicodeString
FeatureName UnicodeString
FailureId UnicodeString
FailureReason UnicodeString
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Recommendation UnicodeString
ErrorCode UnicodeString
ErrorDescription UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Windows Defender",
    "guid": "11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78",
    "event_source_name": "",
    "event_id": 5017,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-06T19:18:49.882801+00:00",
    "event_record_id": 1270,
    "correlation": {},
    "execution": {
      "process_id": 3940,
      "thread_id": 4856
    },
    "channel": "Microsoft-Windows-Windows Defender/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Product Name": "Microsoft Defender Antivirus",
    "Product Version": "4.18.26010.5",
    "Feature Name": "MDE AV Configurations",
    "Failure Id": "0x00000003",
    "Failure Reason": "Group Policy hive was not ready when MDE AV service started and AV configurations might be not as expected.",
    "Recommendation": "Investigate recent changes in Group Policy server settings and reboot the device.",
    "Error Code": "0x80070002",
    "Error Description": "The system cannot find the file specified. "
  },
  "message": ""
}

Example keys not documented in the fields table: Error Code, Error Description, Failure Id, Failure Reason, Feature Name, Product Name, Product Version

References #

Event ID 5100: {Product Name} has entered a grace period and will soon expire.

#
Channel
Operational

Message #

{Product Name} has entered a grace period and will soon expire. After expiration; this program will disable protection against viruses; spyware; and other potentially unwanted software. 	Expiration Reason: {Expiration Reason} 	Expiration Date (UTC): {Expiration Date (UTC)}

References #

Event ID 5101: {Product Name} grace period has expired.

#
Channel
Operational

Message #

{Product Name} grace period has expired. Protection against viruses; spyware; and other potentially unwanted software is disabled. 	Expiration Reason: {Expiration Reason} 	Expiration Date (UTC): {Expiration Date (UTC)} 	Error Code: {Error Code} 	Error Description: {Error Description}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Provenance

ETW provider GUID 11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78

Defined in Windows, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 4.18.26040.7, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 4.18.26040.7, captured 2026-06-02
  • JD-WIN11-22H2-1, sample captured from a live trace, binary version 4.18.26050.15, captured 2026-07-19

    Existing Windows Defender Operational log record retrieved from the lab host.