Hi Sam (TommyZhou-9058),
this is soemthing that comes up from time to time and I think the reply from CyrAz here will give you more details:
Management Pack for Windows Defender generates false alerts
https://social.technet.microsoft.com/Forums/lync/en-US/671424d8-a8e7-4564-b7fc-02db13dc7acf/management-pack-for-windows-defender-generates-false-alerts?forum=operationsmanagermgmtpacks
Can you please check if the mntioned conditions (events and WMI data, gathered through PowerShell) are also met in your case and post a short update here?
Thanks in advance!
----------
(If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)
Regards
Stoyan Chalakov