Defender Event ID 5000: Real-time protection enabled
Real-time protection is enabledDefender event 5000 is logged when real-time protection is turned on — the counterpart of 5001, useful to measure how long protection was off.
5000
- Event ID
- 5000
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 5000 means
Event 5000 records that Microsoft Defender Antivirus real-time protection was enabled. It appears at startup and whenever protection is turned back on after being disabled.
On its own it is routine. Its value is in pairing with 5001: the gap between a 5001 and the next 5000 is the window during which files were not scanned on access.
When it is logged
Audit policy / configuration
None — logged by Microsoft Defender Antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Product Version | Defender platform version. |
Common benign sources
- Boot, platform updates, users re-enabling protection.
What attackers do that produces it
- None directly; marks the end of a window opened by 5001.
Investigation tips
- Pair with the preceding 5001 and list everything that happened on the host in between.
- Frequent 5001/5000 cycles suggest scripted toggling.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.