Distinction between certain Windows Defender events

Christian Green 1 Reputation point
2022-12-19T11:21:30.807+00:00

I am currently working with Windows Defender events and find the documentation to be missing clear explanation around the why there is a distinction between events such as Event Id 1006 - MALWAREPROTECTION_MALWARE_DETECTED and Event Id 1116 - MALWAREPROTECTION_STATE_MALWARE_DETECTED.

It appears to be that events containing Event Id 111? - MALWAREPROTECTION_STATE etc. are used in later versions of Windows.

Is this correct and is it then safe to assume that there would not be the possibility of encountering an event such as Event Id 100? etc. in later versions of Windows?

Thanks for any information around this.

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. S.Sengupta 24,636 Reputation points MVP
    2022-12-20T01:25:28.973+00:00
    0 comments No comments

  2. Limitless Technology 44,766 Reputation points
    2022-12-20T10:14:16.25+00:00

    Hi,

    Thank you for posting your query.

    Kindly follow the steps provided below to resolve your issue.

    Open Event Viewer.

    In the console tree, expand Applications and Services Logs, then Microsoft, then Windows, then Windows Defender.

    Double-click on Operational.

    In the details pane, view the list of individual events to find your event.

    Click the event to see specific details about an event in the lower pane, under the General and Details tabs.

    Go to this link for your reference and other troubleshooting procedures https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-microsoft-defender-antivirus

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/manage-protection-update-schedule-microsoft-defender-antivirus

    Do not hesitate to message us if you need further assistance.

    If the answer is helpful kindly click "Accept as Answer" and up vote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.