Defender Event ID 5007: Configuration changed
- Event ID
- 5007
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 5007 means
Event 5007 records a change to Microsoft Defender Antivirus configuration, with the registry-style setting path in Old Value and New Value. Exclusions, disabled features, sample submission settings and ASR rule changes all appear here.
It is the best place to find exclusions: an entry under \Microsoft\Windows Defender\Exclusions\Paths, \Extensions or \Processes added during an incident is a strong sign an intruder made room for their tools.
When it is logged
None — logged by Microsoft Defender Antivirus.
Also produced in bulk by policy refreshes and platform updates; focus on unusual values.
Key fields
| Field | What it tells you |
|---|---|
| Old Value | Previous setting (registry path and value); may be empty for new settings. |
| New Value | New setting, e.g. HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths\C:\Users\Public = 0x0. |
Common benign sources
- Policy application by Intune, Group Policy or configuration management; product updates.
- Exclusions added by administrators for backup, database or development tools.
What attackers do that produces it
- Adding path, extension or process exclusions (
Add-MpPreference -ExclusionPath). - Disabling features such as real-time monitoring, cloud protection or sample submission.
Investigation tips
- Search New Value for
Exclusions,DisableRealtimeMonitoring,SpyNet,SubmitSamplesConsent. - Tie the change to a process and user via PowerShell logs (4104, 4103), registry auditing (4657, Sysmon 13) or process creation.
- Review whether files were later written to an excluded path.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
4 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- Low · 1
- HighWindows Defender Configuration ChangesRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighWindows Defender Exploit Guard TamperRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumWindows Defender Exclusions AddedRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- LowWindows Defender Submit Sample Feature DisabledRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.