Defender Event ID 5010: Malware scanning disabled
- Event ID
- 5010
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 5010 means
Event 5010 records that Microsoft Defender Antivirus scanning for malware and other potentially unwanted software (the antispyware component) was disabled. Its counterpart 5012 covers virus scanning.
Outside of a third-party antivirus installation, disabling scanning is rarely legitimate and is a common step in attacks that try to switch Defender off through policy or registry settings.
When it is logged
None — logged by Microsoft Defender Antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Product Version | Defender platform version. |
Common benign sources
- Another antivirus product registering and taking over.
What attackers do that produces it
- Tampering through the
DisableAntiSpywarepolicy or registry value, or tools designed to disable Defender.
Investigation tips
- Check 5007 for the setting change and the process that made it (registry and PowerShell logs).
- Confirm whether a third-party AV was installed at that time (Application log, software inventory).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Defender Malware And PUA Scanning DisabledRule by Ján Trenčanský, frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.