Defender Event ID 5012: Virus scanning disabled
- Event ID
- 5012
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 5012 means
Event 5012 records that Microsoft Defender Antivirus scanning for viruses was disabled. Together with 5010 and 5001 it covers the main ways Defender's protection gets turned off.
Legitimate causes are few (a replacement antivirus, a deliberate policy). During an investigation, a 5012 near the start of suspicious activity usually marks the attacker preparing the host.
When it is logged
None — logged by Microsoft Defender Antivirus.
Key fields
| Field | What it tells you |
|---|---|
| Product Version | Defender platform version. |
Common benign sources
- Replacement by a third-party antivirus product.
What attackers do that produces it
- Disabling antivirus scanning through policy or registry settings before running payloads.
Investigation tips
- Correlate with 5007 and 5010 and identify the process and account responsible.
- Scope other hosts for the same change at the same time.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighWindows Defender Virus Scanning Feature DisabledRule by Ján Trenčanský, frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.