Reviewing Microsoft Defender Antivirus event logs for malicious activity


Into_Oblivion1

Active member
Member
Local time
11:07 AM
Posts
189
OS
Windows 11
Dear all

When reviewing event logs for Microsoft Defender Antivirus, and wanting to find out, if something malicious was stopped, quarantined, removed etc.

What else should I consider looking for besides (I know some of them are mentioned more than once):

Detection:
1006
1015
1116
1117
1118
1119 (fail)
1127

Quarantine:
1007
1008
1117
1118
1119

Removal:
1007
1008
1011
1117
1118
1119

Thank you
 
Windows Build/Version
Windows 11

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Why don't you have a look at the Protection History at Security Center?
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 7 5700GMicron Technology DDR4-3200 16GBNVIDIA GeForce RTX 3060
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
HP Pavilion
CPU
AMD Ryzen 7 5700G
Motherboard
Erica6
Memory
Micron Technology DDR4-3200 16GB
Graphics Card(s)
NVIDIA GeForce RTX 3060
Sound Card
Realtek ALC671
Monitor(s) Displays
Samsung SyncMaster U28E590
Screen Resolution
3840 x 2160
Hard Drives
SAMSUNG MZVLQ1T0HALB-000H1
Why don't you have a look at the Protection History at Security Center?

Because event logs for Microsoft Defender Antivirus tells / shows more information?
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
Because event logs for Microsoft Defender Antivirus tells / shows more information?
Good luck figuring out the logs from Microsoft Defender Antivirus.
 

My Computer My Computer

At a glance

Windows 11AMD Ryzen 7 5700GMicron Technology DDR4-3200 16GBNVIDIA GeForce RTX 3060
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
HP Pavilion
CPU
AMD Ryzen 7 5700G
Motherboard
Erica6
Memory
Micron Technology DDR4-3200 16GB
Graphics Card(s)
NVIDIA GeForce RTX 3060
Sound Card
Realtek ALC671
Monitor(s) Displays
Samsung SyncMaster U28E590
Screen Resolution
3840 x 2160
Hard Drives
SAMSUNG MZVLQ1T0HALB-000H1
You can also just call either
Powershell:
Get-MpThreat
# - or -
Get-MpThreatDetection
 

My Computer My Computer

At a glance

Linux Mint
OS
Linux Mint
Computer type
Laptop
Manufacturer/Model
System76 Lemur Pro
There is also 1123 - Remediation completed successfully
5010 - File scanned and determined to be infected
 

My Computer My Computer

At a glance

Linux Mint
OS
Linux Mint
Computer type
Laptop
Manufacturer/Model
System76 Lemur Pro
Good luck figuring out the logs from Microsoft Defender Antivirus.
  1. Open Event Viewer.
  2. In the console tree, expand Applications and Services Logs > Microsoft > Windows > Windows Defender.
  3. Double-click on Operational.
All the codes are explained here:

I assume, that the Security Center, only gives a brief overview of the most important things, and the event log and error codes (above), gives more information?
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
  1. Open Event Viewer.
  2. In the console tree, expand Applications and Services Logs > Microsoft > Windows > Windows Defender.
  3. Double-click on Operational.
All the codes are explained here:
Microsoft Defender Antivirus event IDs and error codes - Microsoft Defender for Endpoint
Look up the causes and solutions for Microsoft Defender Antivirus event IDs and errors.

I assume, that the Security Center, only gives a brief overview of the most important things, and the event log and error codes (above), gives more information?
Can anyone confirm or expand on this?

Thank you
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
I assume, that the Security Center, only gives a brief overview of the most important things, and the event log and error codes (above), gives more information?

Can anyone confirm or expand on this?
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop
"Protection history" has always been empty on my system.

How long can you see Protection history?
Does it empty itself after some time? - some sources says 15-30 days before auto-clear
 

My Computer My Computer

At a glance

Windows 11
OS
Windows 11
Computer type
Laptop

Latest Support Threads

Back
Top Bottom