Defender Event ID 5013: Tamper protection blocked a change
- Event ID
- 5013
- Channel
- Microsoft-Windows-Windows Defender/Operational
- Provider
- Microsoft-Windows-Windows Defender
- Log file
- Microsoft-Windows-Windows Defender%4Operational.evtx
- Category
- Antimalware
- Default logging
- Logged by default
What event 5013 means
Event 5013 records that tamper protection refused a change to a Microsoft Defender Antivirus setting — for example disabling real-time monitoring or adding a setting through the registry. The event states which setting was targeted.
Tamper protection exists precisely to stop malware and intruders from switching Defender off, so a 5013 is evidence of an attempt even though it failed. Administrators changing settings through supported management tools do not trigger it.
When it is logged
None — logged when tamper protection is enabled (the default on current Windows versions with Microsoft Defender).
Key fields
| Field | What it tells you |
|---|---|
| Value | Setting that the blocked change targeted (registry-style path), e.g. ...\Real-Time Protection\DisableRealtimeMonitoring. |
Common benign sources
- Legacy scripts or third-party tools still trying to change Defender settings directly.
What attackers do that produces it
- Attempts to disable Defender through the registry,
Set-MpPreferenceor dedicated tools, blocked by tamper protection.
Investigation tips
- Identify the process and account behind the attempt (PowerShell logs, Sysmon 13, process creation at that time).
- Assume the actor may try other evasion methods next — look for new services, drivers (Sysmon 6) or other security tools stopped.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685 Disable or Modify Tools | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighMicrosoft Defender Tamper Protection TriggerRule by Bhabesh Raj, Nasreddine Bencherchali, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.