- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Detects when the Windows Malware Protection Engine (MsMpEng) crashes.
This detection monitors Windows Error Reporting events where Event ID 1001 is recorded specifically targeting crashes related to the Malware Protection Engine processes. The detection looks for either “MsMpEng” or “mpengine” strings in the error report data, which are associated with the Windows Defender antivirus engine.
The Windows Malware Protection Engine is a critical security component responsible for scanning, detecting, and preventing malware infections. While occasional crashes may occur due to software issues, repeated or suspicious crashes could indicate exploitation attempts or deliberate tampering. Attackers may target antivirus components to disable security protections before deploying additional malicious code.
{{host}}
where the Malware Protection Engine crash occurred.