Skip to content
Microsoft Defender

Defender Event ID 5012: Virus scanning disabled

Scanning for viruses is disabledDefender event 5012 is logged when Defender virus scanning is disabled — like 5010, a strong tampering signal unless another antivirus took over.
5012
Event ID
5012
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 5012 means

Event 5012 records that Microsoft Defender Antivirus scanning for viruses was disabled. Together with 5010 and 5001 it covers the main ways Defender's protection gets turned off.

Legitimate causes are few (a replacement antivirus, a deliberate policy). During an investigation, a 5012 near the start of suspicious activity usually marks the attacker preparing the host.

When it is logged

Audit policy / configuration

None — logged by Microsoft Defender Antivirus.

Key fields

FieldWhat it tells you
Product VersionDefender platform version.

Common benign sources

  • Replacement by a third-party antivirus product.

What attackers do that produces it

  • Disabling antivirus scanning through policy or registry settings before running payloads.

Investigation tips

  • Correlate with 5007 and 5010 and identify the process and account responsible.
  • Scope other hosts for the same change at the same time.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading