Defender Event ID 1119: Critical failure acting on malware
The antimalware platform encountered a critical error when trying to take action on malwareDefender event 1119 records a critical error while acting on a detected threat — remediation failed and the threat may still be active.
1119
- Event ID
- 1119
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 1119 means
Event 1119 is the severe version of 1118: Microsoft Defender Antivirus detected a threat, tried to remediate it and hit a critical error. The threat details and the error are included.
It should be handled as an unremediated infection. Frequent 1119 events on one host can also point to something interfering with Defender itself.
When it is logged
Audit policy / configuration
None — logged by Microsoft Defender Antivirus when it is the active antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Threat Name | Name of the detection. |
| Path | Item that could not be remediated. |
| Action Name | Action that was attempted. |
| Error Code | Error returned. |
| Error Description | Text of that error. |
Common benign sources
- Rare; occasionally corrupt files or storage errors.
What attackers do that produces it
- Malware or tampering preventing remediation.
Investigation tips
- Isolate the host if the threat is not a known PUA; verify manually whether the item is present and running.
- Check for Defender configuration changes (5001, 5007, 5010, 5012) around the same time.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.