PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchAn attempted change to antivirus or endpoint detection and response (EDR) protection is a high-signal investigative lead—not proof on its own that an attacker has compromised the device. Check whether protection actually changed, trace the event to its process, user, and device, and correlate it with nearby activity. Preserve the available evidence and follow your organization’s incident-response plan if the surrounding activity suggests compromise.
1. Find the tampering attempt and its context
In Microsoft Defender for Endpoint, review alerts for attempts to turn off Microsoft Defender Antivirus, change exclusions, stop or modify the EDR sensor, or bypass tamper protection. Open each relevant alert and inspect its affected assets and entities, the reason it triggered, and related events before and after the attempt. Use the process tree and device timeline to identify the initiating process and file, associated user, and affected device.
Microsoft warns that “Tampering attempts might indicate a larger cyberattack.” An alert is not the only place to look: activity that is not correlated with suspicious behavior may not generate an alert but can still appear in the device timeline and Advanced Hunting.
For recent Defender tampering events, Microsoft documents this Advanced Hunting query:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
DeviceEvents
| where Timestamp > ago(10d)
| where ActionType == "TamperingAttempt"
Adjust the time window and add an appropriate device filter for your investigation. Alert titles vary by activity and operating system, so do not rely on one title as a complete search strategy.
2. Determine whether protection was actually disabled
Separate an attempted change from a successful loss of protection. Compare the endpoint’s current security state with its management policy, event logs, and timeline. Establish which setting was targeted, which identity and process initiated the change, and whether protection state changed afterward.
Check Windows Defender state and events
Microsoft documents this PowerShell command for checking Windows Defender’s tamper-protection and real-time-protection states:
Rank #2
Get-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled
Interpret the result alongside the device’s policy and event history; a current status alone does not explain who attempted a change or when. Windows tamper protection can block a setting change even when a local or Group Policy action appears to succeed. Microsoft identifies Event ID 5013 as an event indicating that Defender tamper protection blocked a setting change.
Configuration authority matters, too. Microsoft’s documented precedence is Intune policy over organization-wide portal settings, and portal settings over local Windows Security configuration. A mismatch between a local setting and the effective managed value may therefore reflect policy enforcement rather than a successful attacker change. Tamper protection is on by default for new deployments as part of built-in protection, but its actual state depends on the product, license, onboarding, and management prerequisites.
3. Decide whether the event points to a wider intrusion
Build a timeline around the attempt on the affected device. Correlate preceding and subsequent process activity, account use, configuration or exclusion changes, other alerts, and activity on neighboring devices. Look for a coherent pattern rather than treating the tampering event in isolation. Escalate through your incident-response plan when the evidence indicates malicious activity.
Preserve investigation data before making configuration changes. In Windows Defender troubleshooting mode, Microsoft describes capturing a Defender preference snapshot before and near the end of the mode, and collecting operational logs while it is active. Those records can be available through the portal device timeline, Event Viewer, an investigation package, and Advanced Hunting.
4. Respond without creating a second security problem
Investigate before changing settings
Establish what changed, who or what initiated it, what events surround it, and whether the device’s protection is currently degraded. This helps distinguish an authorized management action or a blocked change from malicious activity.
Use your incident plan if compromise is suspected
Coordinate containment and evidence handling with the incident lead and the owner of the affected endpoint or security tool. The appropriate containment and recovery actions depend on the incident’s scope and your organization’s procedures; the Microsoft guidance cited here does not define a universal sequence for every vendor or incident.
Rank #4
Reserve troubleshooting mode for controlled diagnostics
Microsoft’s Windows troubleshooting mode is intended for temporary testing of specified policy-managed Defender Antivirus settings, not as a general response to suspicious tampering. It can create risk while protection is disabled, and the device must be online for temporary tamper-protection disablement. Changes made during the mode are temporary: when it expires, settings return to their policy-managed values.
For a legitimate diagnostic, collect the relevant process or performance evidence, validate the application or cause, and test only a narrowly scoped exclusion if warranted. Retain the exclusion only if testing confirms it is needed, and restore real-time protection after the test.
Verify recovery and review the records
After remediation or diagnostics, re-check the security state and effective policy, then review the timeline for later activity. For Defender troubleshooting, inspect the before-and-after preference snapshots and operational logs; collect the investigation package when needed.
What differs by platform
Windows with Microsoft Defender
The policy precedence, Event ID 5013 meaning, PowerShell command, and troubleshooting-mode behavior described above apply to Microsoft Defender guidance. Do not assume the same event names, command syntax, policy authority, or restoration behavior applies to another endpoint-security product.
Linux with Microsoft Defender for Endpoint
Microsoft’s cited Linux capability is an audit-mode Preview: it detects and alerts on specified configuration-file modifications, deletions, renames or moves, and Defender process termination or restart activity, including actions by root. Audit mode reports these actions but does not block them. As of September 2026, Microsoft listed version 101.26072.0004 or later from Insiders-Slow, supported distributions and kernels, and a gradual rollout to eligible devices. Preview eligibility and prerequisites can change, so verify the current requirements before relying on this capability.
Other endpoint-security products
Alert coverage, searchable telemetry, operating-system behavior, policy precedence, and response options vary by product. Consult the affected product’s current official documentation and your organization’s playbook rather than transferring Defender-specific details to another tool.
Questions to ask when evaluating tamper detection
- Does the product detect attempts to stop its service or sensor, and changes to configuration or exclusions?
- Do events provide process, user, device, and timeline context?
- Can administrators search for relevant activity when no alert fires?
- On each supported operating system, does the product block a change or only audit and report it?
- How do policy authority and temporary diagnostic modes affect configuration and restoration?
- What investigation actions and evidence-retention options are available?
These are useful comparison criteria, not a vendor ranking: the cited Microsoft documentation does not establish a cross-vendor comparison.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

