DFIR Reference v0.1

Windows Defender Event Reference

Reference for Microsoft Defender Antivirus forensic analysis. Covers the Microsoft-Windows-Windows Defender/Operational log plus a System log corroboration event. Focused on malware detection events, defense evasion (real-time protection disable, exclusion abuse), and Tamper Protection indicators.

12Event IDs
2Log Channels
6Sigma Rules
System / Security CenterWindows Defender/Operational
Showing 12 of 12 events

⚡ Sigma Detection Rules — Windows Defender Event Reference

Curated highest-signal Sigma-style detection rules for Windows Defender Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.

Convert to your SIEM: sigconverter.io

6 detection rules 9 event IDs covered
Copied!