Skip to content
Microsoft Defender

Defender Event ID 5001: Real-time protection disabled

Real-time protection is disabledDefender event 5001 is logged when real-time protection is turned off — a classic step before attackers drop tools or ransomware.
5001
Event ID
5001
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 5001 means

Event 5001 records that Microsoft Defender Antivirus real-time protection was disabled, whether through the Windows Security UI, Group Policy, PowerShell (Set-MpPreference -DisableRealtimeMonitoring $true) or the registry.

Intruders disable real-time protection to run credential dumpers, remote access tools and ransomware without interference. Tamper protection blocks many of these changes on current systems (logged as 5013 instead), so a successful 5001 on a managed host is especially significant.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus.

A third-party antivirus taking over also disables Defender's real-time protection.

Key fields

FieldWhat it tells you
Product VersionDefender platform version.

Common benign sources

  • Administrators temporarily disabling protection for troubleshooting or software installs.
  • Installation of a third-party antivirus.

What attackers do that produces it

  • Disabling protection with PowerShell, Group Policy or registry edits before deploying tools or ransomware.

Investigation tips

  • Find who and what disabled it — 4104 / 4103 PowerShell logs, process creation of powershell.exe or reg.exe, and 5007 configuration changes at the same time.
  • Measure the window until the next 5000 and review file and process activity in it.
  • Check other hosts for 5001 at the same time — mass disabling indicates a domain-wide action (for example a GPO change, 5136).

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading