Event ID 1009 — ProductName has restored an item from quarantine.
Description
ProductName has restored an item from quarantine.
Message #
Fields #
| Name | Description |
|---|---|
ProductName UnicodeString | — |
ProductVersion UnicodeString | — |
Unused UnicodeString | — |
Unused2 UnicodeString | — |
Unused3 UnicodeString | — |
Unused4 UnicodeString | — |
Unused5 UnicodeString | — |
Domain UnicodeString | — |
User UnicodeString | — |
SID UnicodeString | — |
ThreatName UnicodeString | — |
ThreatID UnicodeString | — |
SeverityID UnicodeString | — |
CategoryID UnicodeString | — |
FWLink UnicodeString | — |
Path UnicodeString | — |
Unused6 UnicodeString | — |
Unused7 UnicodeString | — |
Unused8 UnicodeString | — |
Unused9 UnicodeString | — |
Unused10 UnicodeString | — |
Unused11 UnicodeString | — |
Unused12 UnicodeString | — |
Unused13 UnicodeString | — |
SeverityName UnicodeString | — |
CategoryName UnicodeString | — |
SecurityintelligenceVersion UnicodeString | — |
EngineVersion UnicodeString | — |
Detection Rules #
View all rules referencing this event →
Sigma # view in reference
- Win Defender Restored Quarantine File source high: Detects the restoration of files from the defender quarantine