Skip to content
Microsoft Defender

Defender Event ID 5013: Tamper protection blocked a change

Tamper protection blocked a change to Microsoft Defender AntivirusDefender event 5013 is logged when tamper protection blocks a change to Defender settings — evidence that something tried to weaken the antivirus.
5013
Event ID
5013
Channel
Microsoft-Windows-Windows Defender/Operational
Provider
Microsoft-Windows-Windows Defender
Log file
Microsoft-Windows-Windows Defender%4Operational.evtx
Category
Antimalware
Default logging
Logged by default

What event 5013 means

Event 5013 records that tamper protection refused a change to a Microsoft Defender Antivirus setting — for example disabling real-time monitoring or adding a setting through the registry. The event states which setting was targeted.

Tamper protection exists precisely to stop malware and intruders from switching Defender off, so a 5013 is evidence of an attempt even though it failed. Administrators changing settings through supported management tools do not trigger it.

When it is logged

Audit policy / configuration

None — logged when tamper protection is enabled (the default on current Windows versions with Microsoft Defender).

Key fields

FieldWhat it tells you
ValueSetting that the blocked change targeted (registry-style path), e.g. ...\Real-Time Protection\DisableRealtimeMonitoring.

Common benign sources

  • Legacy scripts or third-party tools still trying to change Defender settings directly.

What attackers do that produces it

  • Attempts to disable Defender through the registry, Set-MpPreference or dedicated tools, blocked by tamper protection.

Investigation tips

  • Identify the process and account behind the attempt (PowerShell logs, Sysmon 13, process creation at that time).
  • Assume the actor may try other evasion methods next — look for new services, drivers (Sysmon 6) or other security tools stopped.

MITRE ATT&CK techniques

TechniqueTactics
T1685 Disable or Modify ToolsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading