Skip to content
Microsoft Defender

Defender Event ID 5000: Real-time protection enabled

Real-time protection is enabledDefender event 5000 is logged when real-time protection is turned on — the counterpart of 5001, useful to measure how long protection was off.
5000
Event ID
5000
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 5000 means

Event 5000 records that Microsoft Defender Antivirus real-time protection was enabled. It appears at startup and whenever protection is turned back on after being disabled.

On its own it is routine. Its value is in pairing with 5001: the gap between a 5001 and the next 5000 is the window during which files were not scanned on access.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus.

Key fields

FieldWhat it tells you
Product VersionDefender platform version.

Common benign sources

  • Boot, platform updates, users re-enabling protection.

What attackers do that produces it

  • None directly; marks the end of a window opened by 5001.

Investigation tips

  • Pair with the preceding 5001 and list everything that happened on the host in between.
  • Frequent 5001/5000 cycles suggest scripted toggling.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading