Skip to content
Microsoft Defender

Defender Event ID 1006: Malware found by scan

The antimalware engine found malware or other potentially unwanted softwareDefender event 1006 is logged when the antimalware engine finds malware or unwanted software, with threat name, path and detection source.
1006
Event ID
1006
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1006 means

Event 1006 is an engine-level detection record: the antimalware engine found malware or potentially unwanted software, typically during a scan. It carries the threat name, the path, and where and how it was detected.

In current Defender versions the detection state events 1116/1117 are the main records; 1006/1007 appear alongside them, especially for scan results. Treat either as a detection and look for the remediation outcome.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
Threat NameName of the detection.
Severity NameSeverity of the threat.
PathWhere the item was found.
Detection UserUser context.

Common benign sources

  • Scans finding PUA, adware or test files.

What attackers do that produces it

  • Malware or tools found by a scheduled or on-demand scan after the fact.

Investigation tips

  • Correlate with 1116/1117 at the same time for remediation status.
  • Use the path's timestamps (file system, Sysmon 11) to date when the item arrived.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading