Windows Defender windefend Event 1013: Malware detection history deletion

Alerts when Windows Defender deletes its malware/PUA detection history via windefend Event ID 1013.

FreeReviewedSigma · Informational · v2
Product
windows
Service
windefend
Author
Cian Heasley (SigmaHQ), DRL 1.1
Published
2020-08-13
Updated
2026-07-31

What it detects

This rule identifies Windows Defender antimalware events where the platform deletes the history of detected malware and potentially unwanted software. Attackers or administrators may trigger this to reduce forensic visibility of prior detections. The detection relies on the windefend log telemetry, specifically EventID 1013.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.