Defender Event ID 1007: Action taken (engine)
The antimalware platform performed an action to protect your system from malwareDefender event 1007 records that the antimalware platform took action on detected malware, the engine-level counterpart of event 1117.
1007
- Event ID
- 1007
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1007 means
Event 1007 is logged when Defender successfully applied an action (quarantine, remove, clean) to an item it detected. It mirrors 1117 and usually follows a 1006.
Use it to confirm remediation of scan detections and to find what was removed from a host during an incident.
When it is logged
Audit policy / configuration
None — logged by Microsoft Defender Antivirus when it is the active antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Name of the detection. |
| Path | Item acted upon. |
| Action Name | Action applied. |
| Detection User | User context. |
Common benign sources
- Quarantine of PUA and test files during scans.
What attackers do that produces it
- Removal of attacker tooling, which can explain gaps in an intruder's activity.
Investigation tips
- Pair with 1006 to get the detection details and time.
- Quarantined items can be recovered for analysis from the Defender quarantine store.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.