Defender Event ID 1008: Engine action failed
The antimalware platform attempted to perform an action but the action failedDefender event 1008 means Defender could not complete an action on detected malware (engine level); the item may still be on the system.
1008
- Event ID
- 1008
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1008 means
Event 1008 is logged when Defender tried to act on a detected item and failed, with the error that prevented it. It is the engine-level counterpart of 1118.
The threat should be considered present until a later successful action is recorded or the item is removed manually.
When it is logged
Audit policy / configuration
None — logged by Microsoft Defender Antivirus when it is the active antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Name of the detection. |
| Path | Item that could not be handled. |
| Action Name | Action attempted. |
| Error Code | Error returned. |
Common benign sources
- Locked or in-use files, read-only locations.
What attackers do that produces it
- Active malware preventing its own removal.
Investigation tips
- Verify whether the item still exists and runs; remediate manually.
- Check for a later 1007 or 1117 on the same path.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.