Microsoft Security Essentials and Defender

From Michael's Information Zone
Jump to navigation Jump to search

Text output for email reporting

[1][2]

wevtutil qe ForwardedEvents "/q:*[System[(EventID=1116)]]" /f:text /rd:true /c:1

Event IDs

[3]

  • 1116 : MALWAREPROTECTION_STATE_MALWARE_DETECTED
  • 1117 : MALWAREPROTECTION_STATE_MALWARE_ACTION_TAKEN
  • 1118 : MALWAREPROTECTION_STATE_MALWARE_ACTION_FAILED
  • 1119 : MALWAREPROTECTION_STATE_MALWARE_ACTION_CRITICALLY_FAILED
  • 5001 : MALWAREPROTECTION_RTP_DISABLED
  • https://social.technet.microsoft.com/Forums/windowsserver/en-US/cc6bd0a4-59ab-4d32-9f3d-a822d428d08a/wevtutil-event-filter?forum=winserverManagement
  • https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil
  • https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/troubleshoot-windows-defender-antivirus