Skip to content
Microsoft Defender

Defender Event ID 5007: Configuration changed

The antimalware platform configuration changedDefender event 5007 logs every Defender configuration change with old and new values — including exclusions added by attackers.
5007
Event ID
5007
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 5007 means

Event 5007 records a change to Microsoft Defender Antivirus configuration, with the registry-style setting path in Old Value and New Value. Exclusions, disabled features, sample submission settings and ASR rule changes all appear here.

It is the best place to find exclusions: an entry under \Microsoft\Windows Defender\Exclusions\Paths, \Extensions or \Processes added during an incident is a strong sign an intruder made room for their tools.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus.

Also produced in bulk by policy refreshes and platform updates; focus on unusual values.

Key fields

FieldWhat it tells you
Old ValuePrevious setting (registry path and value); may be empty for new settings.
New ValueNew setting, e.g. HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\C:\Users\Public = 0x0.

Common benign sources

  • Policy application by Intune, Group Policy or configuration management; product updates.
  • Exclusions added by administrators for backup, database or development tools.

What attackers do that produces it

  • Adding path, extension or process exclusions (Add-MpPreference -ExclusionPath).
  • Disabling features such as real-time monitoring, cloud protection or sample submission.

Investigation tips

  • Search New Value for Exclusions, DisableRealtimeMonitoring, SpyNet, SubmitSamplesConsent.
  • Tie the change to a process and user via PowerShell logs (4104, 4103), registry auditing (4657, Sysmon 13) or process creation.
  • Review whether files were later written to an excluded path.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment
T1112 Modify RegistryDefense Impairment, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

4 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading