Defender Event ID 1116: Malware detected
- Event ID
- 1116
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1116 means
Event 1116 is the detection record of Microsoft Defender Antivirus: something matched a signature, heuristic or cloud verdict. It names the threat, where it was found (Path), which process touched it, which user was involved and which component caught it (Source Name: real-time protection, a scan, AMSI, downloads…).
A detection is followed by 1117 when the remediation action succeeded, or 1118/1119 when it failed. A 1116 without a successful 1117 means the threat may still be on disk or running.
For incident response the detection time and path are anchors: the process that wrote the file, the user session and the network activity just before it usually explain how it arrived.
When it is logged
None — logged by Microsoft Defender Antivirus in the Windows Defender/Operational channel whenever it is the active antivirus.
When a third-party antivirus is active, Defender runs in passive or disabled mode and these events may be absent.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Name of the detection, e.g. HackTool:Win32/Mimikatz or Trojan:PowerShell/.... The prefix gives the threat type. |
| Severity Name | Severity (Low, Moderate, High, Severe). |
| Category Name | Threat category (Trojan, Tool, Exploit, Potentially Unwanted Software…). |
| Path | File, script or resource where the threat was found (may list several file:_ / containerfile:_ entries). |
| Process Name | Process that accessed or created the detected item. |
| Detection User | Account in whose context the detection happened. |
| Source Name | Component that detected it — Real-Time Protection, User or System scan, IOAV (downloads and attachments), AMSI (scripts), ELAM (boot) and others. |
| Detection Origin Name | Where the item came from (Local machine, Network share, Internet…). |
Common benign sources
- Potentially unwanted applications, adware and cracked software on user machines.
- Security tools and test files (EICAR, pentest tools) used by IT or red teams.
What attackers do that produces it
- Credential dumping and hacking tools dropped by an intruder (HackTool detections are rarely benign on servers).
- Malicious scripts caught through AMSI (Source Name AMSI), often PowerShell download cradles.
- Ransomware and loader payloads — the first detection is frequently one step of a larger intrusion.
Investigation tips
- Check for the matching 1117 (action succeeded); treat 1118/1119 or no follow-up as an active threat.
- Pivot on Process Name and the time to process creation (4688, Sysmon 1) to find the parent chain.
- For AMSI detections, read the 4104 script blocks from the same minute.
- Look for configuration changes (5001, 5007) shortly before or after — attackers often try to disable Defender after a detection.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- HighWindows Defender AMSI Trigger DetectedRule by Bhabesh Raj, SigmaHQ, DRL 1.1
- HighWindows Defender Threat DetectedRule by Ján Trenčanský, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 1117Action taken on malwareMicrosoft Defender
- 1118Action on malware failedMicrosoft Defender
- 1119Critical failure acting on malwareMicrosoft Defender
- 1006Malware found by scanMicrosoft Defender
- 5001Real-time protection disabledMicrosoft Defender
- 4104Script block loggingPowerShell Operational
- 1Process creationSysmon