Skip to content
Microsoft Defender

Defender Event ID 1116: Malware detected

The antimalware platform detected malware or other potentially unwanted softwareDefender event 1116 is logged when Microsoft Defender Antivirus detects malware or unwanted software: threat name, file path, process and user.
1116
Event ID
1116
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1116 means

Event 1116 is the detection record of Microsoft Defender Antivirus: something matched a signature, heuristic or cloud verdict. It names the threat, where it was found (Path), which process touched it, which user was involved and which component caught it (Source Name: real-time protection, a scan, AMSI, downloads…).

A detection is followed by 1117 when the remediation action succeeded, or 1118/1119 when it failed. A 1116 without a successful 1117 means the threat may still be on disk or running.

For incident response the detection time and path are anchors: the process that wrote the file, the user session and the network activity just before it usually explain how it arrived.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus in the Windows Defender/Operational channel whenever it is the active antivirus.

When a third-party antivirus is active, Defender runs in passive or disabled mode and these events may be absent.

Key fields

FieldWhat it tells you
Threat NameName of the detection, e.g. HackTool:Win32/Mimikatz or Trojan:PowerShell/.... The prefix gives the threat type.
Severity NameSeverity (Low, Moderate, High, Severe).
Category NameThreat category (Trojan, Tool, Exploit, Potentially Unwanted Software…).
PathFile, script or resource where the threat was found (may list several file:_ / containerfile:_ entries).
Process NameProcess that accessed or created the detected item.
Detection UserAccount in whose context the detection happened.
Source NameComponent that detected it — Real-Time Protection, User or System scan, IOAV (downloads and attachments), AMSI (scripts), ELAM (boot) and others.
Detection Origin NameWhere the item came from (Local machine, Network share, Internet…).

Common benign sources

  • Potentially unwanted applications, adware and cracked software on user machines.
  • Security tools and test files (EICAR, pentest tools) used by IT or red teams.

What attackers do that produces it

  • Credential dumping and hacking tools dropped by an intruder (HackTool detections are rarely benign on servers).
  • Malicious scripts caught through AMSI (Source Name AMSI), often PowerShell download cradles.
  • Ransomware and loader payloads — the first detection is frequently one step of a larger intrusion.

Investigation tips

  • Check for the matching 1117 (action succeeded); treat 1118/1119 or no follow-up as an active threat.
  • Pivot on Process Name and the time to process creation (4688, Sysmon 1) to find the parent chain.
  • For AMSI detections, read the 4104 script blocks from the same minute.
  • Look for configuration changes (5001, 5007) shortly before or after — attackers often try to disable Defender after a detection.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading