← Event ID reference
1116

Microsoft Defender Antivirus detected malware

  • Log: Microsoft-Windows-Windows Defender/Operational
  • Source: Microsoft-Windows-Windows Defender
  • Defender
  • Critical

What it means

Defender found malware or unwanted software. 1117 is logged when it takes action (quarantine or remove).

Why it matters

A detection without a matching 1117 means the threat may still be active.

What to do

  • Confirm a 1117 followed.
  • Isolate the device if the threat wasn’t removed.
  • Find how it arrived: email, download or USB.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Microsoft-Windows-Windows Defender/Operational'; Id = 1116
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us