Defender Event ID 1015: Suspicious behavior detected
- Event ID
- 1015
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1015 means
Event 1015 comes from Defender's behavior monitoring: a process did something suspicious (for example a sequence of actions typical of an attack tool), rather than a file matching a signature. The event includes the behavior-based threat name and the process involved.
Behavior detections often catch fileless or living-off-the-land activity that signature scans miss, so they deserve the same attention as 1116.
When it is logged
None — logged by Microsoft Defender Antivirus when behavior monitoring (part of real-time protection) is enabled.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Behavior detection name (often prefixed Behavior:). |
| Path | Process or file associated with the behavior. |
| Process Name | Process that exhibited the behavior. |
| Detection User | User context. |
Common benign sources
- Administrative tools or installers with aggressive behavior; security testing.
What attackers do that produces it
- Credential access attempts, process injection, suspicious script behavior caught at run time.
Investigation tips
- Reconstruct the process tree with 4688 / Sysmon 1 and read any 4104 script blocks around the time.
- Check whether a 1116/1117 follows with an action.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Defender Threat DetectedRule by Ján Trenčanský, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.