The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect protection healthGet-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IsTamperProtectedView examples
Inspect Defender serviceGet-Service -Name WinDefend | Select-Object Name, Status, StartTypeView examples
Audit protection preferencesGet-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, PUAProtectionView examples
Check intelligence freshnessGet-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AntivirusSignatureAgeView examples
Request an intelligence updateUpdate-MpSignatureView examples
Start a quick scanStart-MpScan -ScanType QuickScanView examples
Scan one approved pathStart-MpScan -ScanType CustomScan -ScanPath 'C:\Inbound'View examples
Review scan timestampsGet-MpComputerStatus | Select-Object QuickScanStartTime, QuickScanEndTime, FullScanStartTime, FullScanEndTimeView examples
List detection historyGet-MpThreatDetection | Sort-Object InitialDetectionTime -DescendingView examples
List known threatsGet-MpThreat | Select-Object ThreatID, ThreatName, SeverityID, CategoryID, IsActive, DidThreatExecuteView examples
Read key Defender eventsGet-WinEvent -FilterHashtable ` @{LogName='Microsoft-Windows-Windows Defender/Operational'; ` Id=1116,1117,1118,5007} -MaxEvents 100View examples
Inventory exclusionsGet-MpPreference | Select-Object ExclusionPath, ExclusionExtension, ExclusionProcessView examples
Add one narrow path exclusionAdd-MpPreference -ExclusionPath 'C:\Vendor\App\Cache'View examples
Remove one path exclusionRemove-MpPreference -ExclusionPath 'C:\Vendor\App\Cache'View examples
Check tamper protectionGet-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabledView examples
Record Defender performanceNew-MpPerformanceRecording -RecordTo ` 'C:\Temp\Defender-scans.etl' -Seconds 120View examples
Report high-impact filesGet-MpPerformanceReport -Path ` 'C:\Temp\Defender-scans.etl' -TopFiles 20 ` -TopProcesses 20View examples
Start Defender OfflineStart-MpWDOScanView examples

Microsoft Defender Antivirus health is a combination of engine and service state, protection features, security-intelligence freshness, policy, detections, and successful remediation. Read them together rather than trusting one green flag. Prefer centrally managed policy, investigate unexpected configuration changes, and treat every exclusion or protection reduction as a documented security exception. Many configuration, remediation, tracing, and offline-scan operations require an elevated Windows PowerShell session and some do not support WhatIf.

Step by step

Detailed examples

01

Build a health baseline from multiple signals

Get-MpComputerStatus reports operational protection state, Get-MpPreference reports configuration, and WinDefend shows service state. Interpret Disable-prefixed preferences carefully: False normally means the feature is not disabled. A third-party antivirus, passive mode, platform differences, managed policy, tamper protection, or Windows Server configuration can change what is expected. Start read-only; use elevation when the endpoint withholds details.

Read-only endpoint protection baseline
Get-Service -Name WinDefend | Select-Object Name, Status, StartType
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, AntispywareEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, NISEnabled, IsTamperProtected
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, PUAProtection
Back to quick reference ↑
02

Measure intelligence freshness before forcing an update source

Security intelligence, antivirus engine, and platform versions are different components. Check version, timestamp, and age, then compare with organizational compliance thresholds and update-source policy. Update-MpSignature changes endpoint state and has no WhatIf support. Without an explicit source it follows configured fallback order; forcing MicrosoftUpdateServer can bypass the intended diagnostic path and still cannot repair every WSUS, proxy, platform, or connectivity problem.

Inspect update state and approved source policy
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AntivirusSignatureAge
Get-MpPreference | Select-Object SignatureFallbackOrder, SignatureDefinitionUpdateFileSharesSources
# Update-MpSignature changes state and has no WhatIf; run elevated only under the approved update workflow.
Back to quick reference ↑
03

Match scan scope to evidence and production load

A quick scan examines common persistence and active-threat locations; a full scan can be lengthy and I/O intensive; a custom scan narrows work to a verified path. Start-MpScan does not offer WhatIf. Schedule disruptive scans around service demand, ensure the path exists, update intelligence first when appropriate, and monitor completion and detections rather than treating successful command submission as a clean result.

Review scan history and an intended custom scope
$scanPath = 'C:\Inbound'
if (-not (Test-Path -LiteralPath $scanPath -PathType Container)) { throw 'Approved scan path is missing.' }
Get-MpComputerStatus | Select-Object QuickScanStartTime, QuickScanEndTime, FullScanStartTime, FullScanEndTime
# Start-MpScan -ScanType CustomScan -ScanPath $scanPath has no WhatIf and may affect workload performance.
Back to quick reference ↑
04

Investigate detection instances before overriding remediation

Get-MpThreat summarizes known threats, while Get-MpThreatDetection returns active and past detection instances with paths, sources, times, actions, and errors where available. Preserve incident evidence and coordinate with the security team before deleting files, restoring quarantine, allowing an item, or rerunning remediation. Output can expose usernames, sensitive paths, shares, and filenames, so restrict exports and redact them before tickets or chat.

Correlate threat and detection records
Get-MpThreat | Select-Object ThreatID, ThreatName, SeverityID, CategoryID, IsActive, DidThreatExecute
Get-MpThreatDetection | Sort-Object InitialDetectionTime -Descending | Select-Object InitialDetectionTime, ThreatID, ActionSuccess, Resources, DetectionSourceType, LastThreatStatusChangeTime
# Treat Resources and user-context fields as potentially sensitive incident data.
Back to quick reference ↑
05

Use the operational log as an incident timeline

Event 1116 records a detection, 1117 an action, 1118 an action failure, and 5007 a configuration change. Correlate events by host, time, threat identity, path, action, and result rather than reading one event in isolation. An unexpected 5007 can indicate unauthorized or malicious configuration change. Event absence can reflect retention, forwarding, logging, or product state and is not proof that no event occurred.

Read recent high-value Defender events
$filter = @{ LogName = 'Microsoft-Windows-Windows Defender/Operational'; Id = 1116, 1117, 1118, 5007; StartTime = (Get-Date).AddDays(-7) }
Get-WinEvent -FilterHashtable $filter -ErrorAction Stop | Select-Object TimeCreated, Id, LevelDisplayName, Message
Back to quick reference ↑
06

Treat every exclusion as a scoped, expiring protection gap

Microsoft states that exclusions lower protection and usually are not needed. First measure the actual compatibility or performance problem. Prefer the narrowest file or contextual scope over a folder, extension, or process; process exclusions cover files opened by that process and can also affect network protection and attack-surface-reduction inspection. Add-MpPreference appends, while Set-MpPreference can replace an entire exclusion list. These cmdlets require elevation, change state immediately, and do not support WhatIf. Central policy can merge, overwrite, or hide exclusions.

Inventory and review a proposed exception without applying it
$p = Get-MpPreference
'ExclusionPath','ExclusionExtension','ExclusionProcess' | ForEach-Object {
  $type = $_
  $p.$type | ForEach-Object { [pscustomobject]@{ Type = $type; Value = $_ } }
}
[pscustomobject]@{ ProposedPath = 'C:\Vendor\App\Cache'; Owner = 'Application team'; Expiry = '2026-09-12'; Applied = $false }
Back to quick reference ↑
07

Respect central policy and tamper-protection boundaries

Local PowerShell changes are not authoritative in a managed estate: Intune, Microsoft Defender for Endpoint security settings management, Configuration Manager, and Group Policy can overwrite them. Tamper protection intentionally blocks protected security-setting changes; do not disable it or attempt registry workarounds. Use approved troubleshooting mode when supported, identify the owning policy and assignment, make the change centrally, and verify effective endpoint state after policy refresh.

Read local evidence before tracing policy ownership
Get-MpComputerStatus | Select-Object IsTamperProtected, AntivirusEnabled, RealTimeProtectionEnabled
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, PUAProtection
Get-WinEvent -FilterHashtable @{ LogName = 'Microsoft-Windows-Windows Defender/Operational'; Id = 5007 } -MaxEvents 20
# Compare with the assigned central policy; do not bypass tamper protection.
Back to quick reference ↑
08

Measure scan cost before weakening protection

Defender Performance Analyzer records antimalware-engine and kernel process events, then ranks expensive paths, extensions, files, and processes. Collection requires elevation and adds some load. ETL and reports can reveal sensitive file paths and process activity, so store, share, and delete them under incident-data policy. A hot path is a diagnostic lead, not automatic justification for an exclusion; fix application I/O patterns, scheduling, or product issues first.

Plan a bounded, privacy-aware performance trace
$trace = 'C:\Temp\Defender-scans.etl'
[pscustomobject]@{ Path = $trace; DurationSeconds = 120; RequiresElevation = $true; MayContainSensitivePaths = $true } | Format-List
# New-MpPerformanceRecording -RecordTo $trace -Seconds 120 records endpoint activity.
# Get-MpPerformanceReport -Path $trace -TopFiles 20 -TopProcesses 20 analyzes the approved trace.
Back to quick reference ↑
09

Reserve Defender Offline for planned escalation

Microsoft Defender Offline restarts into a trusted environment to scan threats that can hide while Windows is running. Start-MpWDOScan is disruptive, has no WhatIf mode, and can restart the device; save work, notify users, verify BitLocker recovery access, preserve incident evidence, and schedule downtime first. After Windows returns, review operational events and detections. On BitLocker-protected systems, recovery readiness matters whenever the boot path changes.

Preflight an offline-scan change without starting it
Get-MpComputerStatus | Select-Object AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Get-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus
[pscustomobject]@{ Command = 'Start-MpWDOScan'; ImmediateRestartRisk = $true; RecoveryVerified = $false; ApprovedDowntime = $false } | Format-List
# Do not run until recovery access, evidence handling, user notification, and downtime are approved.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftUse PowerShell cmdlets to configure and run Microsoft Defender Antiviruslearn.microsoft.com
  2. MicrosoftMicrosoft Defender Antivirus PowerShell modulelearn.microsoft.com
  3. MicrosoftConfigure custom exclusions for Microsoft Defender Antiviruslearn.microsoft.com
  4. MicrosoftExclusions in Microsoft Defender Antiviruslearn.microsoft.com
  5. MicrosoftMicrosoft Defender Antivirus event IDs and error codeslearn.microsoft.com
  6. MicrosoftMicrosoft Defender Antivirus Performance Analyzer referencelearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback