Skip to content
Microsoft Defender

Defender Event ID 1117: Action taken on malware

The antimalware platform performed an action to protect your system from malware or other potentially unwanted softwareDefender event 1117 confirms Microsoft Defender Antivirus acted on a detection — quarantine, remove, clean or block — with threat, path and action.
1117
Event ID
1117
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1117 means

Event 1117 follows a detection (1116) when Microsoft Defender Antivirus successfully applied an action: the item was quarantined, removed, cleaned or blocked. It repeats the threat details and adds the action taken (Action Name).

It is the "closure" record for a detection, but not proof the incident is over: the file may have run before it was caught, and other components of the same intrusion may not be detected at all.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
Threat NameName of the detection.
PathItem that was acted upon.
Process NameProcess involved in the detection.
Detection UserUser context of the detection.
Action NameAction applied (Quarantine, Remove, Clean, Block, Allow…).
Source NameDetecting component (Real-Time Protection, AMSI, scan…).

Common benign sources

  • Routine quarantine of adware, PUA and test files.

What attackers do that produces it

  • Payloads blocked during an intrusion; repeated 1117 for the same threat means the attacker keeps retrying.

Investigation tips

  • Pair with the preceding 1116; the time difference shows how long the item existed before action.
  • Search for the same threat name or path on other hosts — the intrusion may not be limited to this one.
  • Check whether the process that dropped the item is itself legitimate or also malicious.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading