Microsoft Defender Logs
Also called Defender event log, MPLog, Windows Defender Operational log, antivirus logs forensics.
- PLATFORM
- Windows
- CATEGORY
- Program Execution
- INDEX
- 18 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
Antivirus detection and scan records that name file paths, detected tool families, process images, and changes to protection settings such as newly added scan exclusions.
Where it lives
Microsoft-Windows-Windows Defender/Operational event log, and the support logs under C:\ProgramData\Microsoft\Windows Defender\Support\
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of microsoft defender logs” is neither.
What it records
The operational event log records detections and the action taken, along with configuration changes: real-time protection being disabled, and settings being altered, including the addition of exclusion paths. The plain-text support logs record scanning activity in far more detail, including paths of files scanned and images of processes observed, which is why they are often more probative than the event log. Both are byproducts of protection rather than an evidence facility, and their content and format vary with the platform version.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a file matching a known tool or malware family was present at a named path at a recorded time
- That protection was disabled, or that an exclusion covering a specific path was added — and when, relative to other activity
- File paths and process images observed during scanning, including those of programs that left no other trace
- That a file was quarantined or removed by the product rather than by a user, which changes the spoliation analysis materially
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That a detected file was executed. Detection records presence and scanning, and the product scans files that were never run
- Who added an exclusion or disabled protection. The event records the change, and attribution to an account requires the Security log or management-platform records
- Intent behind a configuration change. Exclusions are added routinely for legitimate performance and compatibility reasons, and treating one as evidence of concealment without context is an overreach
- A complete scanning history. Support logs roll on size, and the operational channel is capped like any other event log
- That a clean system was clean. Detection depends on the signatures and detection logic in force at the time of the scan, not at the time of the examination
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Showing that exclusions were added by IT policy or by an administrator for ordinary reasons, breaking the concealment inference
- Establishing that the support logs had rolled before the period at issue
- Arguing that a detection name identifies a family heuristically rather than identifying a specific binary
- Pointing out that a third-party product may have been the active engine, leaving the built-in logs sparse for reasons unrelated to the conduct
What survives, and for how long
Operational events persist until the channel rolls. The support logs are plain text, roll on size, and on an active system may cover only weeks — but because they record paths of files scanned, they sometimes retain the only surviving reference to a file that was created and deleted between other artifacts' snapshots.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Can antivirus logs show that a hacking tool was on a computer?
Often yes. Defender's operational log records detections with the file path and the action taken, and its support logs record paths scanned and process images observed. Between them they can establish that a named tool was present at a path on a date, even where the file itself has been deleted. Detection is evidence of presence, not of execution.
Does adding a Defender exclusion prove someone was hiding something?
No, though it is worth investigating. Exclusions are added routinely by administrators and by software installers for performance and compatibility reasons, and the event records the change without recording a reason or, on its own, an account. What makes an exclusion probative is its timing and its target — an exclusion for a directory created minutes earlier is a different fact from a standing policy exclusion.
What is the Defender MPLog and why does it matter?
It is a plain-text support log written under the Defender program data directory that records scanning activity in far more detail than the event channel, including paths of files scanned and images of processes observed. Because scanning touches files that leave no other trace, it sometimes holds the only surviving reference to a file created and deleted between the snapshots other artifacts take.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
Process Creation Events (4688)
A Security log record written each time a process starts, naming the account, the executable, the parent process and — if separately enabled — the full command line.
EDR Telemetry
Security-agent telemetry recording process execution with command lines and hashes, file operations, and outbound network connections — the richest endpoint record available, retained on the vendor's terms.
AmCache
A registry hive maintained by the compatibility appraiser recording that binaries were present on the system, with their paths, publishers, sizes and a SHA-1 of the file.
Whether the microsoft defender logsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.