The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect protection health | Get-MpComputerStatus |
Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IsTamperProtected | View examples |
| Inspect Defender service | Get-Service -Name WinDefend |
Select-Object Name, Status, StartType | View examples |
| Audit protection preferences | Get-MpPreference |
Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, PUAProtection | View examples |
| Check intelligence freshness | Get-MpComputerStatus |
Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AntivirusSignatureAge | View examples |
| Request an intelligence update | Update-MpSignature | View examples |
| Start a quick scan | Start-MpScan -ScanType QuickScan | View examples |
| Scan one approved path | Start-MpScan -ScanType CustomScan -ScanPath 'C:\Inbound' | View examples |
| Review scan timestamps | Get-MpComputerStatus |
Select-Object QuickScanStartTime, QuickScanEndTime, FullScanStartTime, FullScanEndTime | View examples |
| List detection history | Get-MpThreatDetection |
Sort-Object InitialDetectionTime -Descending | View examples |
| List known threats | Get-MpThreat |
Select-Object ThreatID, ThreatName, SeverityID, CategoryID, IsActive, DidThreatExecute | View examples |
| Read key Defender events | Get-WinEvent -FilterHashtable `
@{LogName='Microsoft-Windows-Windows Defender/Operational'; `
Id=1116,1117,1118,5007} -MaxEvents 100 | View examples |
| Inventory exclusions | Get-MpPreference |
Select-Object ExclusionPath, ExclusionExtension, ExclusionProcess | View examples |
| Add one narrow path exclusion | Add-MpPreference -ExclusionPath 'C:\Vendor\App\Cache' | View examples |
| Remove one path exclusion | Remove-MpPreference -ExclusionPath 'C:\Vendor\App\Cache' | View examples |
| Check tamper protection | Get-MpComputerStatus |
Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabled | View examples |
| Record Defender performance | New-MpPerformanceRecording -RecordTo `
'C:\Temp\Defender-scans.etl' -Seconds 120 | View examples |
| Report high-impact files | Get-MpPerformanceReport -Path `
'C:\Temp\Defender-scans.etl' -TopFiles 20 `
-TopProcesses 20 | View examples |
| Start Defender Offline | Start-MpWDOScan | View examples |
Microsoft Defender Antivirus health is a combination of engine and service state, protection features, security-intelligence freshness, policy, detections, and successful remediation. Read them together rather than trusting one green flag. Prefer centrally managed policy, investigate unexpected configuration changes, and treat every exclusion or protection reduction as a documented security exception. Many configuration, remediation, tracing, and offline-scan operations require an elevated Windows PowerShell session and some do not support WhatIf.
Step by step
Detailed examples
Build a health baseline from multiple signals
Get-MpComputerStatus reports operational protection state, Get-MpPreference reports configuration, and WinDefend shows service state. Interpret Disable-prefixed preferences carefully: False normally means the feature is not disabled. A third-party antivirus, passive mode, platform differences, managed policy, tamper protection, or Windows Server configuration can change what is expected. Start read-only; use elevation when the endpoint withholds details.
Get-Service -Name WinDefend | Select-Object Name, Status, StartType
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, AntispywareEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, NISEnabled, IsTamperProtected
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, PUAProtection Measure intelligence freshness before forcing an update source
Security intelligence, antivirus engine, and platform versions are different components. Check version, timestamp, and age, then compare with organizational compliance thresholds and update-source policy. Update-MpSignature changes endpoint state and has no WhatIf support. Without an explicit source it follows configured fallback order; forcing MicrosoftUpdateServer can bypass the intended diagnostic path and still cannot repair every WSUS, proxy, platform, or connectivity problem.
Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AntivirusSignatureAge
Get-MpPreference | Select-Object SignatureFallbackOrder, SignatureDefinitionUpdateFileSharesSources
# Update-MpSignature changes state and has no WhatIf; run elevated only under the approved update workflow. Match scan scope to evidence and production load
A quick scan examines common persistence and active-threat locations; a full scan can be lengthy and I/O intensive; a custom scan narrows work to a verified path. Start-MpScan does not offer WhatIf. Schedule disruptive scans around service demand, ensure the path exists, update intelligence first when appropriate, and monitor completion and detections rather than treating successful command submission as a clean result.
$scanPath = 'C:\Inbound'
if (-not (Test-Path -LiteralPath $scanPath -PathType Container)) { throw 'Approved scan path is missing.' }
Get-MpComputerStatus | Select-Object QuickScanStartTime, QuickScanEndTime, FullScanStartTime, FullScanEndTime
# Start-MpScan -ScanType CustomScan -ScanPath $scanPath has no WhatIf and may affect workload performance. Investigate detection instances before overriding remediation
Get-MpThreat summarizes known threats, while Get-MpThreatDetection returns active and past detection instances with paths, sources, times, actions, and errors where available. Preserve incident evidence and coordinate with the security team before deleting files, restoring quarantine, allowing an item, or rerunning remediation. Output can expose usernames, sensitive paths, shares, and filenames, so restrict exports and redact them before tickets or chat.
Get-MpThreat | Select-Object ThreatID, ThreatName, SeverityID, CategoryID, IsActive, DidThreatExecute
Get-MpThreatDetection | Sort-Object InitialDetectionTime -Descending | Select-Object InitialDetectionTime, ThreatID, ActionSuccess, Resources, DetectionSourceType, LastThreatStatusChangeTime
# Treat Resources and user-context fields as potentially sensitive incident data. Use the operational log as an incident timeline
Event 1116 records a detection, 1117 an action, 1118 an action failure, and 5007 a configuration change. Correlate events by host, time, threat identity, path, action, and result rather than reading one event in isolation. An unexpected 5007 can indicate unauthorized or malicious configuration change. Event absence can reflect retention, forwarding, logging, or product state and is not proof that no event occurred.
$filter = @{ LogName = 'Microsoft-Windows-Windows Defender/Operational'; Id = 1116, 1117, 1118, 5007; StartTime = (Get-Date).AddDays(-7) }
Get-WinEvent -FilterHashtable $filter -ErrorAction Stop | Select-Object TimeCreated, Id, LevelDisplayName, Message Treat every exclusion as a scoped, expiring protection gap
Microsoft states that exclusions lower protection and usually are not needed. First measure the actual compatibility or performance problem. Prefer the narrowest file or contextual scope over a folder, extension, or process; process exclusions cover files opened by that process and can also affect network protection and attack-surface-reduction inspection. Add-MpPreference appends, while Set-MpPreference can replace an entire exclusion list. These cmdlets require elevation, change state immediately, and do not support WhatIf. Central policy can merge, overwrite, or hide exclusions.
$p = Get-MpPreference
'ExclusionPath','ExclusionExtension','ExclusionProcess' | ForEach-Object {
$type = $_
$p.$type | ForEach-Object { [pscustomobject]@{ Type = $type; Value = $_ } }
}
[pscustomobject]@{ ProposedPath = 'C:\Vendor\App\Cache'; Owner = 'Application team'; Expiry = '2026-09-12'; Applied = $false } Respect central policy and tamper-protection boundaries
Local PowerShell changes are not authoritative in a managed estate: Intune, Microsoft Defender for Endpoint security settings management, Configuration Manager, and Group Policy can overwrite them. Tamper protection intentionally blocks protected security-setting changes; do not disable it or attempt registry workarounds. Use approved troubleshooting mode when supported, identify the owning policy and assignment, make the change centrally, and verify effective endpoint state after policy refresh.
Get-MpComputerStatus | Select-Object IsTamperProtected, AntivirusEnabled, RealTimeProtectionEnabled
Get-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, PUAProtection
Get-WinEvent -FilterHashtable @{ LogName = 'Microsoft-Windows-Windows Defender/Operational'; Id = 5007 } -MaxEvents 20
# Compare with the assigned central policy; do not bypass tamper protection. Measure scan cost before weakening protection
Defender Performance Analyzer records antimalware-engine and kernel process events, then ranks expensive paths, extensions, files, and processes. Collection requires elevation and adds some load. ETL and reports can reveal sensitive file paths and process activity, so store, share, and delete them under incident-data policy. A hot path is a diagnostic lead, not automatic justification for an exclusion; fix application I/O patterns, scheduling, or product issues first.
$trace = 'C:\Temp\Defender-scans.etl'
[pscustomobject]@{ Path = $trace; DurationSeconds = 120; RequiresElevation = $true; MayContainSensitivePaths = $true } | Format-List
# New-MpPerformanceRecording -RecordTo $trace -Seconds 120 records endpoint activity.
# Get-MpPerformanceReport -Path $trace -TopFiles 20 -TopProcesses 20 analyzes the approved trace. Reserve Defender Offline for planned escalation
Microsoft Defender Offline restarts into a trusted environment to scan threats that can hide while Windows is running. Start-MpWDOScan is disruptive, has no WhatIf mode, and can restart the device; save work, notify users, verify BitLocker recovery access, preserve incident evidence, and schedule downtime first. After Windows returns, review operational events and detections. On BitLocker-protected systems, recovery readiness matters whenever the boot path changes.
Get-MpComputerStatus | Select-Object AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Get-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus
[pscustomobject]@{ Command = 'Start-MpWDOScan'; ImmediateRestartRisk = $true; RecoveryVerified = $false; ApprovedDowntime = $false } | Format-List
# Do not run until recovery access, evidence handling, user notification, and downtime are approved. Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftUse PowerShell cmdlets to configure and run Microsoft Defender Antiviruslearn.microsoft.com
- MicrosoftMicrosoft Defender Antivirus PowerShell modulelearn.microsoft.com
- MicrosoftConfigure custom exclusions for Microsoft Defender Antiviruslearn.microsoft.com
- MicrosoftExclusions in Microsoft Defender Antiviruslearn.microsoft.com
- MicrosoftMicrosoft Defender Antivirus event IDs and error codeslearn.microsoft.com
- MicrosoftMicrosoft Defender Antivirus Performance Analyzer referencelearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



