Defender Event ID 5001: Real-time protection disabled
- Event ID
- 5001
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 5001 means
Event 5001 records that Microsoft Defender Antivirus real-time protection was disabled, whether through the Windows Security UI, Group Policy, PowerShell (Set-MpPreference -DisableRealtimeMonitoring $true) or the registry.
Intruders disable real-time protection to run credential dumpers, remote access tools and ransomware without interference. Tamper protection blocks many of these changes on current systems (logged as 5013 instead), so a successful 5001 on a managed host is especially significant.
When it is logged
None — logged by Microsoft Defender Antivirus.
A third-party antivirus taking over also disables Defender's real-time protection.
Key fields
| Field | What it tells you |
|---|---|
| Product Version | Defender platform version. |
Common benign sources
- Administrators temporarily disabling protection for troubleshooting or software installs.
- Installation of a third-party antivirus.
What attackers do that produces it
- Disabling protection with PowerShell, Group Policy or registry edits before deploying tools or ransomware.
Investigation tips
- Find who and what disabled it — 4104 / 4103 PowerShell logs, process creation of
powershell.exeorreg.exe, and 5007 configuration changes at the same time. - Measure the window until the next 5000 and review file and process activity in it.
- Check other hosts for 5001 at the same time — mass disabling indicates a domain-wide action (for example a GPO change, 5136).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Defender Real-time Protection DisabledRule by Ján Trenčanský, frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.