SKIP TO CONTENT
PROGRAM EXECUTION18 / 36

Microsoft Defender Logs

Also called Defender event log, MPLog, Windows Defender Operational log, antivirus logs forensics.

PLATFORM
Windows
CATEGORY
Program Execution
INDEX
18 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

Antivirus detection and scan records that name file paths, detected tool families, process images, and changes to protection settings such as newly added scan exclusions.

Where it lives

Microsoft-Windows-Windows Defender/Operational event log, and the support logs under C:\ProgramData\Microsoft\Windows Defender\Support\

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of microsoft defender logs” is neither.

What it records

The operational event log records detections and the action taken, along with configuration changes: real-time protection being disabled, and settings being altered, including the addition of exclusion paths. The plain-text support logs record scanning activity in far more detail, including paths of files scanned and images of processes observed, which is why they are often more probative than the event log. Both are byproducts of protection rather than an evidence facility, and their content and format vary with the platform version.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a file matching a known tool or malware family was present at a named path at a recorded time
  • That protection was disabled, or that an exclusion covering a specific path was added — and when, relative to other activity
  • File paths and process images observed during scanning, including those of programs that left no other trace
  • That a file was quarantined or removed by the product rather than by a user, which changes the spoliation analysis materially

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • That a detected file was executed. Detection records presence and scanning, and the product scans files that were never run
  • Who added an exclusion or disabled protection. The event records the change, and attribution to an account requires the Security log or management-platform records
  • Intent behind a configuration change. Exclusions are added routinely for legitimate performance and compatibility reasons, and treating one as evidence of concealment without context is an overreach
  • A complete scanning history. Support logs roll on size, and the operational channel is capped like any other event log
  • That a clean system was clean. Detection depends on the signatures and detection logic in force at the time of the scan, not at the time of the examination

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Showing that exclusions were added by IT policy or by an administrator for ordinary reasons, breaking the concealment inference
  • Establishing that the support logs had rolled before the period at issue
  • Arguing that a detection name identifies a family heuristically rather than identifying a specific binary
  • Pointing out that a third-party product may have been the active engine, leaving the built-in logs sparse for reasons unrelated to the conduct

What survives, and for how long

Operational events persist until the channel rolls. The support logs are plain text, roll on size, and on an active system may cover only weeks — but because they record paths of files scanned, they sometimes retain the only surviving reference to a file that was created and deleted between other artifacts' snapshots.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Can antivirus logs show that a hacking tool was on a computer?

Often yes. Defender's operational log records detections with the file path and the action taken, and its support logs record paths scanned and process images observed. Between them they can establish that a named tool was present at a path on a date, even where the file itself has been deleted. Detection is evidence of presence, not of execution.

Does adding a Defender exclusion prove someone was hiding something?

No, though it is worth investigating. Exclusions are added routinely by administrators and by software installers for performance and compatibility reasons, and the event records the change without recording a reason or, on its own, an account. What makes an exclusion probative is its timing and its target — an exclusion for a directory created minutes earlier is a different fact from a standing policy exclusion.

What is the Defender MPLog and why does it matter?

It is a plain-text support log written under the Defender program data directory that records scanning activity in far more detail than the event channel, including paths of files scanned and images of processes observed. Because scanning touches files that leave no other trace, it sometimes holds the only surviving reference to a file created and deleted between the snapshots other artifacts take.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the microsoft defender logsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.