Skip to main content

Windows Defender / Security Service

Log NameEvent IDSeverityDescription
Microsoft-Windows-Windows Defender/Operational1000InformationWindows Defender service started successfully
Microsoft-Windows-Windows Defender/Operational1001InformationWindows Defender service stopped
Microsoft-Windows-Windows Defender/Operational1002InformationReal-time protection started
Microsoft-Windows-Windows Defender/Operational1003WarningReal-time protection stopped
Microsoft-Windows-Windows Defender/Operational1004ErrorWindows Defender initialization failed
Microsoft-Windows-Windows Defender/Operational1005InformationEngine version updated
Microsoft-Windows-Windows Defender/Operational1006InformationSignature definitions updated successfully
Microsoft-Windows-Windows Defender/Operational1007WarningSignature definitions update failed
Microsoft-Windows-Windows Defender/Operational1008WarningMalware found and remediation started
Microsoft-Windows-Windows Defender/Operational1009InformationMalware removed or quarantined successfully
Microsoft-Windows-Windows Defender/Operational1010InformationScan started (manual or scheduled)
Microsoft-Windows-Windows Defender/Operational1011InformationScan completed successfully
Microsoft-Windows-Windows Defender/Operational1012ErrorScan failed to complete
Microsoft-Windows-Windows Defender/Operational1116WarningMalware or potentially unwanted software detected
Microsoft-Windows-Windows Defender/Operational1117WarningPotentially unwanted application detected
Microsoft-Windows-Windows Defender/Operational1118InformationMalware action successful
Microsoft-Windows-Windows Defender/Operational1119ErrorMalware action failed
Microsoft-Windows-Windows Defender/Operational1120InformationFile or process excluded from scanning
Microsoft-Windows-Windows Defender/Operational2000WarningSuspicious behavior detected by real-time protection
Microsoft-Windows-Windows Defender/Operational2001ErrorBehavior monitoring service failed
Microsoft-Windows-Windows Defender/Operational3002WarningTamper protection blocked unauthorized change
Microsoft-Windows-Windows Defender/Operational5001ErrorCritical AV engine error
Microsoft-Windows-Windows Defender/Operational5004InformationConfiguration changed
Microsoft-Windows-Windows Defender/Operational5010ErrorService health check failure
Microsoft-Windows-Windows Defender/Operational5012WarningSignature definitions expired
System7036InformationWindows Defender service entered running or stopped state
System7000ErrorWindows Defender service failed to start
System7024ErrorWindows Defender service terminated unexpectedly
Security5007InformationWindows Defender settings modified
Security1118InformationMalware protection configuration changed
Security1119WarningSecurity intelligence update failed
Microsoft-Windows-Windows Defender/Operational1006CriticalMalware detected
Microsoft-Windows-Windows Defender/Operational1116HighMalware remediation failed
Microsoft-Windows-Windows Defender/Operational1117MediumThreat removed successfully
Microsoft-Windows-Windows Defender/Operational2001CriticalReal-time protection disabled
Microsoft-Windows-Windows Defender/Operational5001HighSignature update failed
Microsoft-Windows-Security-Mitigations1HighExploit mitigation blocked a process