Skip to content
Microsoft Defender

Defender Event ID 1119: Critical failure acting on malware

The antimalware platform encountered a critical error when trying to take action on malwareDefender event 1119 records a critical error while acting on a detected threat — remediation failed and the threat may still be active.
1119
Event ID
1119
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 1119 means

Event 1119 is the severe version of 1118: Microsoft Defender Antivirus detected a threat, tried to remediate it and hit a critical error. The threat details and the error are included.

It should be handled as an unremediated infection. Frequent 1119 events on one host can also point to something interfering with Defender itself.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus when it is the active antivirus.

Key fields

FieldWhat it tells you
Threat NameName of the detection.
PathItem that could not be remediated.
Action NameAction that was attempted.
Error CodeError returned.
Error DescriptionText of that error.

Common benign sources

  • Rare; occasionally corrupt files or storage errors.

What attackers do that produces it

  • Malware or tampering preventing remediation.

Investigation tips

  • Isolate the host if the threat is not a known PUA; verify manually whether the item is present and running.
  • Check for Defender configuration changes (5001, 5007, 5010, 5012) around the same time.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading