Skip to content
Microsoft Defender

Defender Event ID 1013: Detection history deleted

The antimalware platform deleted history of malware and other potentially unwanted softwareDefender event 1013 is logged when Defender's malware detection history is deleted — routine purging, or an attempt to hide past detections.
1013
Event ID
1013
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1013 means

Event 1013 records that Microsoft Defender Antivirus removed items from its detection history. Defender purges old history automatically after a retention period, so the event is normally routine.

It becomes interesting when it appears right after detections during an incident, or when triggered by a user rather than the system: clearing history hides what was detected from the Defender UI (the Operational log entries remain unless the log is cleared too).

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
TimestampTime up to which history was deleted.
DomainDomain of the account that triggered the deletion.
UserAccount that triggered the deletion (often SYSTEM for automatic purges).

Common benign sources

  • Automatic history cleanup by Defender after the retention period.

What attackers do that produces it

  • An intruder clearing Defender history to hide detections of their tools.

Investigation tips

  • Check the User field; a named account instead of SYSTEM deserves a question.
  • Look for 1116/1117 shortly before, and for other anti-forensics (1102, 104).

MITRE ATT&CK techniques

TechniqueTactics
T1070 Indicator RemovalStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading