Skip to content
Microsoft Defender

Defender Event ID 1008: Engine action failed

The antimalware platform attempted to perform an action but the action failedDefender event 1008 means Defender could not complete an action on detected malware (engine level); the item may still be on the system.
1008
Event ID
1008
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1008 means

Event 1008 is logged when Defender tried to act on a detected item and failed, with the error that prevented it. It is the engine-level counterpart of 1118.

The threat should be considered present until a later successful action is recorded or the item is removed manually.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
Threat NameName of the detection.
PathItem that could not be handled.
Action NameAction attempted.
Error CodeError returned.

Common benign sources

  • Locked or in-use files, read-only locations.

What attackers do that produces it

  • Active malware preventing its own removal.

Investigation tips

  • Verify whether the item still exists and runs; remediate manually.
  • Check for a later 1007 or 1117 on the same path.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading