Defender Event ID 1013: Detection history deleted
- Event ID
- 1013
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1013 means
Event 1013 records that Microsoft Defender Antivirus removed items from its detection history. Defender purges old history automatically after a retention period, so the event is normally routine.
It becomes interesting when it appears right after detections during an incident, or when triggered by a user rather than the system: clearing history hides what was detected from the Defender UI (the Operational log entries remain unless the log is cleared too).
When it is logged
None — logged by Microsoft Defender Antivirus when it is the active antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Timestamp | Time up to which history was deleted. |
| Domain | Domain of the account that triggered the deletion. |
| User | Account that triggered the deletion (often SYSTEM for automatic purges). |
Common benign sources
- Automatic history cleanup by Defender after the retention period.
What attackers do that produces it
- An intruder clearing Defender history to hide detections of their tools.
Investigation tips
- Check the User field; a named account instead of SYSTEM deserves a question.
- Look for 1116/1117 shortly before, and for other anti-forensics (1102, 104).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1070 Indicator Removal | Stealth |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Info · 1
- InfoWindows Defender Malware Detection History DeletionRule by Cian Heasley, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.