Skip to content
Microsoft Defender

Defender Event ID 1007: Action taken (engine)

The antimalware platform performed an action to protect your system from malwareDefender event 1007 records that the antimalware platform took action on detected malware, the engine-level counterpart of event 1117.
1007
Event ID
1007
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1007 means

Event 1007 is logged when Defender successfully applied an action (quarantine, remove, clean) to an item it detected. It mirrors 1117 and usually follows a 1006.

Use it to confirm remediation of scan detections and to find what was removed from a host during an incident.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
Threat NameName of the detection.
PathItem acted upon.
Action NameAction applied.
Detection UserUser context.

Common benign sources

  • Quarantine of PUA and test files during scans.

What attackers do that produces it

  • Removal of attacker tooling, which can explain gaps in an intruder's activity.

Investigation tips

  • Pair with 1006 to get the detection details and time.
  • Quarantined items can be recovered for analysis from the Defender quarantine store.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading