1116
Microsoft Defender Antivirus detected malware
- Log: Microsoft-Windows-Windows Defender/Operational
- Source: Microsoft-Windows-Windows Defender
- Defender
- Critical
What it means
Defender found malware or unwanted software. 1117 is logged when it takes action (quarantine or remove).
Why it matters
A detection without a matching 1117 means the threat may still be active.
What to do
- Confirm a 1117 followed.
- Isolate the device if the threat wasn’t removed.
- Find how it arrived: email, download or USB.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Microsoft-Windows-Windows Defender/Operational'; Id = 1116
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us