Defender Event ID 1117: Action taken on malware
- Event ID
- 1117
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1117 means
Event 1117 follows a detection (1116) when Microsoft Defender Antivirus successfully applied an action: the item was quarantined, removed, cleaned or blocked. It repeats the threat details and adds the action taken (Action Name).
It is the "closure" record for a detection, but not proof the incident is over: the file may have run before it was caught, and other components of the same intrusion may not be detected at all.
When it is logged
None — logged by Microsoft Defender Antivirus when it is the active antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Name of the detection. |
| Path | Item that was acted upon. |
| Process Name | Process involved in the detection. |
| Detection User | User context of the detection. |
| Action Name | Action applied (Quarantine, Remove, Clean, Block, Allow…). |
| Source Name | Detecting component (Real-Time Protection, AMSI, scan…). |
Common benign sources
- Routine quarantine of adware, PUA and test files.
What attackers do that produces it
- Payloads blocked during an intrusion; repeated 1117 for the same threat means the attacker keeps retrying.
Investigation tips
- Pair with the preceding 1116; the time difference shows how long the item existed before action.
- Search for the same threat name or path on other hosts — the intrusion may not be limited to this one.
- Check whether the process that dropped the item is itself legitimate or also malicious.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Defender Threat DetectedRule by Ján Trenčanský, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.