Defender Event ID 1006: Malware found by scan
- Event ID
- 1006
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1006 means
Event 1006 is an engine-level detection record: the antimalware engine found malware or potentially unwanted software, typically during a scan. It carries the threat name, the path, and where and how it was detected.
In current Defender versions the detection state events 1116/1117 are the main records; 1006/1007 appear alongside them, especially for scan results. Treat either as a detection and look for the remediation outcome.
When it is logged
None — logged by Microsoft Defender Antivirus when it is the active antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Name of the detection. |
| Severity Name | Severity of the threat. |
| Path | Where the item was found. |
| Detection User | User context. |
Common benign sources
- Scans finding PUA, adware or test files.
What attackers do that produces it
- Malware or tools found by a scheduled or on-demand scan after the fact.
Investigation tips
- Correlate with 1116/1117 at the same time for remediation status.
- Use the path's timestamps (file system, Sysmon 11) to date when the item arrived.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Defender Threat DetectedRule by Ján Trenčanský, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.