Skip to content
Microsoft Defender

Defender Event ID 1015: Suspicious behavior detected

The antimalware platform detected suspicious behaviorDefender event 1015 is logged when behavior monitoring detects suspicious activity rather than a known file, with threat name and process details.
1015
Event ID
1015
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1015 means

Event 1015 comes from Defender's behavior monitoring: a process did something suspicious (for example a sequence of actions typical of an attack tool), rather than a file matching a signature. The event includes the behavior-based threat name and the process involved.

Behavior detections often catch fileless or living-off-the-land activity that signature scans miss, so they deserve the same attention as 1116.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when behavior monitoring (part of real-time protection) is enabled.

Key fields

FieldWhat it tells you
Threat NameBehavior detection name (often prefixed Behavior:).
PathProcess or file associated with the behavior.
Process NameProcess that exhibited the behavior.
Detection UserUser context.

Common benign sources

  • Administrative tools or installers with aggressive behavior; security testing.

What attackers do that produces it

  • Credential access attempts, process injection, suspicious script behavior caught at run time.

Investigation tips

  • Reconstruct the process tree with 4688 / Sysmon 1 and read any 4104 script blocks around the time.
  • Check whether a 1116/1117 follows with an action.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading