Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file

Alerts on WinDefend 1119 remediation failures involving TieringEngineService.exe marked with EICAR content or triggered by RedSun.exe.

FreeReviewedSigma · Critical · v5
Product
windows
Service
windefend
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-04-17
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows Defender real-time protection events (EventID 1119) where remediation fails for TieringEngineService.exe staged in a temporary RS-{GUID} directory with an EICAR test filename indicator, or when RedSun.exe is present. Attackers may use this kind of staging and scanning-race behavior to interfere with or bypass security controls and pivot into execution. The detection relies on windefend telemetry capturing EventID 1119 along with the file path, ThreatName ending in EICAR_Test_File, and/or process name ending in RedSun.exe.

Related detections9 linkedT1036.005 — drag to rearrange
Suspicious svchost Masquerading Executed Outside System Directory
Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Suspicious ALPHA SPIDER Rclone Exfiltration Tool Masquerading as System Binary (via process_creation)
Suspicious Axios NPM macOS Persistence Masquerading as Apple Service
Suspicious Office Application Spawning Script Or Shell Interpreter
Malicious Spoolsv Process Masquerading From Non-System Path (via process_creation)
Suspicious svchost.exe Execution From AppData Roaming Directory
Malicious StyleSmuggler (CVE-2026-75650) Post-Exploitation Implant Process (via process_creation)
Suspicious Network Connection From wabmig.exe (Turian Injection)
Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file
Pivot detection · T1036.005 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.