Detection rules › Sigma

Windows Defender Malware Detection History Deletion

Severity
informational
Author
Cian Heasley
Source
upstream

Windows Defender logs when the history of detected infections is deleted.

Event coverage

ProviderEvent IDTitle
Windows-Defender1013

Stages and Predicates

Stage 1: selection