Skip to content
Microsoft Defender

Defender Event ID 1118: Action on malware failed

The antimalware platform attempted to perform an action but the action failedDefender event 1118 means Microsoft Defender Antivirus detected a threat but could not remediate it (non-critical failure) — the item may still be present.
1118
Event ID
1118
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1118 means

Event 1118 is logged when Defender tried to act on a detection and hit a non-critical error, for example because the file was locked or in use. The threat details are included, plus the error code describing why the action failed.

Unlike 1117, it leaves the threat unresolved. Treat it as an open detection until a later successful action (1117) or manual cleanup is confirmed.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
Threat NameName of the detection.
PathItem Defender failed to remediate.
Action NameAction that was attempted.
Error CodeError returned by the attempted action.
Error DescriptionText of that error.

Common benign sources

  • Files held open by legitimate applications, backups or network shares Defender cannot write to.

What attackers do that produces it

  • Running malware that protects its files, or payloads on shares the host cannot modify.

Investigation tips

  • Check whether the file still exists and whether its process is running.
  • Look for a later 1117 for the same path; if none, remediate manually and scope the intrusion.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading