Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Microsoft Network Realtime Inspection Service (NisSrv.exe) is a legitimate Microsoft Defender Antivirus component that provides network inspection protection. It normally runs in the background when Defender is active, and its presence alone does not indicate malware. Verify the file’s location and Microsoft digital signature before troubleshooting unusually high CPU, memory, or disk usage.

The process may appear under several related names: Microsoft Network Realtime Inspection Service in Task Manager’s Processes view, NisSrv.exe in the Details view, and Microsoft Defender Antivirus Network Inspection Service in the Services console. The associated Windows service name is WdNisSvc.

Microsoft documents these names and their relationship in its Microsoft Defender Antivirus process and service reference. The important distinction is that a genuine Defender process is normal, while a malicious program can imitate the filename.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Key takeaways

  • NisSrv.exe is the executable associated with Microsoft Defender Antivirus Network Realtime Inspection Service, also known as the WdNisSvc service.
  • NisSrv.exe and MsMpEng.exe are separate Defender components; MsMpEng.exe is commonly displayed as Antimalware Service Executable.
  • A Microsoft signature and a credible Defender installation location are stronger evidence of legitimacy than the filename alone.
  • Temporary activity during scans, downloads, software installation, archive extraction, builds, or updates is not automatically a problem.
  • Persistent high resource usage should be diagnosed with Defender’s performance analyzer before adding exclusions or disabling protection.
  • Deleting, forcibly disabling, or taking ownership of Defender files is not a safe routine fix because it weakens malware protection and may not solve the underlying issue.

What does Microsoft Network Realtime Inspection Service do?

Microsoft Network Realtime Inspection Service is a Microsoft Defender Antivirus protection component that inspects network-related activity for signs associated with malware and other threats. It is not a general-purpose Windows networking service, a packet-capture tool, or a replacement for Microsoft Defender Firewall.

#1 Best Overall
Bitdefender Total Security 2026 – Complete Antivirus and Internet Security Suite – 5 Devices | 1 Year Subscription | PC/Mac | Activation Code by Mail
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
  • SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
  • ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
  • ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.

The word “network” in the name does not mean that NisSrv.exe is evidence that Microsoft is recording everything you do online. Network inspection, Defender Antivirus real-time protection, Windows Security’s Network Protection feature, and Microsoft Defender Firewall are related security layers, but they are not interchangeable features.

Defender’s real-time protection can monitor files and programs as they are accessed or executed. Microsoft explains the behavior in its Windows Security virus and threat protection guidance. A process appearing in Task Manager means that the component is present or active; it does not, by itself, mean Defender has found an infection.

What is the difference between NisSrv.exe, WdNisSvc, and MsMpEng.exe?

NisSrv.exe is the process file, WdNisSvc is the associated service name, and MsMpEng.exe is the main Microsoft Defender Antivirus service process. They belong to the same security product but perform different roles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Item Where you may see it Role
NisSrv.exe Task Manager > Details Executable associated with Defender’s Network Inspection service.
Microsoft Network Realtime Inspection Service Task Manager > Processes User-facing process label for the network inspection component.
WdNisSvc Services console or PowerShell Windows service name for Microsoft Defender Antivirus Network Inspection Service.
MsMpEng.exe Task Manager, usually “Antimalware Service Executable” Main Microsoft Defender Antivirus service process.
MpCmdRun.exe Usually a temporary command-line process Microsoft Defender Antivirus command-line utility, not normally a continuously running service.

Because the components are separate, NisSrv.exe and MsMpEng.exe can show different resource patterns. Microsoft’s current Defender process documentation provides the current process and service naming.

Why is NisSrv.exe running right now?

NisSrv.exe is usually running because Microsoft Defender Antivirus is enabled and its real-time protection is active. Defender may inspect activity when a file, program, download, archive, or other content is accessed, opened, executed, or changed.

Common, legitimate triggers include:

  • Opening or downloading a file.
  • Installing or updating software.
  • Extracting a large or compressed archive.
  • Running a full, quick, custom, or scheduled scan.
  • Working in a large development project or build directory.
  • Starting a virtual machine, game, or other application that reads and writes many files.
  • Receiving a Microsoft Defender security-intelligence or platform update.
  • Another security product not currently taking over Defender’s antivirus role.

“Running” does not mean that NisSrv.exe is currently detecting malware. Resource activity has to be interpreted alongside what the computer is doing and what Windows Security reports.

Is NisSrv.exe safe or could it be malware?

NisSrv.exe is normally safe when the executable belongs to Microsoft Defender, has a valid Microsoft digital signature, and is located in a credible Windows Defender installation directory. The filename alone cannot authenticate a program because malware can copy familiar Windows filenames.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to verify the executable

  1. Open Task Manager with Ctrl + Shift + Esc.
  2. Select the Details tab.
  3. Locate NisSrv.exe.
  4. Right-click the process and choose Open file location.
  5. Right-click the file, choose Properties, and open the Digital Signatures tab.
  6. Check that the signer is Microsoft and that Windows reports the signature as valid.
  7. Open Windows Security > Virus & threat protection and check for current threats, protection-history entries, or warnings that protection is disabled.

Do not treat one hard-coded path as a universal test. Windows Defender platform files can be stored in versioned Defender directories, and enterprise, server, and managed-device configurations can differ. The path is useful supporting evidence, but the signature and Windows Security status matter too.

You can check the signature from PowerShell by replacing the example path with the actual path shown by Open file location:

Rank #2
Sale
Webroot Internet Security Plus Antivirus Software 2026 3 Device 1 Year Download for PC/Mac/Chromebook/Android/IOS + Password Manager
  • POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
  • IDENTITY THEFT PROTECTION AND ANTI-PHISHING: Webroot protects your personal information against keyloggers, spyware, and other online threats and warns you of potential danger before you click
  • ALWAYS UP TO DATE: Webroot scours 95% of the internet three times per day including billions of web pages, files and apps to determine what is safe online and enhances the software automatically without time-consuming updates
  • SUPPORTS ALL DEVICES: Compatible with PC, MAC, Chromebook, Mobile Smartphones and Tablets including Windows, macOS, Apple iOS and Android
  • NEW SECURITY DESIGNED FOR CHROMEBOOKS: Chromebooks are susceptible to fake applications, bad browser extensions and malicious web content; close these security gaps with extra protection specifically designed to safeguard your Chromebook
Get-AuthenticodeSignature "C:fullpathtoNisSrv.exe"

A genuine Microsoft binary should show a valid Microsoft signature. An unexpected directory, missing or invalid signature, malformed file, Defender alert, or unexplained duplicate process deserves investigation rather than dismissal.

Does NisSrv.exe monitor every website or replace the firewall?

No. Microsoft Network Realtime Inspection Service is a Defender security component, but its name should not be interpreted as proof that it watches every website or functions as Microsoft Defender Firewall.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Network inspection and Network Protection address different parts of Windows security. Network Protection can help prevent access to malicious or suspicious locations when configured and supported, while the firewall controls network traffic according to firewall rules. Microsoft’s Network Protection configuration documentation should be consulted when managing that separate feature.

Is high CPU, memory, or disk usage normal?

High resource usage from NisSrv.exe is a symptom to investigate, not proof that the service is broken or that the computer is infected. There is no single CPU or memory number that is “normal” for every Windows installation because usage varies with hardware, Defender platform version, Windows edition, and workload.

Short-lived activity can be expected during:

  • Scanning many files.
  • Copying, extracting, or compiling large amounts of data.
  • Installing or updating applications.
  • Running development, virtualization, gaming, or source-code workloads.
  • Security-intelligence or Defender platform updates.

Persistent usage after the triggering task ends can have other causes, including repeated access to a problematic file or directory, software that constantly rewrites files, interaction with another security product, Defender or Windows corruption, a false positive, or a malicious file that Defender is repeatedly examining.

How should you troubleshoot high NisSrv.exe usage?

Use the least disruptive diagnostic sequence below. Do not begin by killing the process or disabling all Defender protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Check whether the activity has an obvious cause

Note what was happening when usage increased. Installing software, extracting an archive, opening a large project, running a build, starting a virtual machine, or launching a game can cause temporary inspection activity. If resource use falls after the operation finishes, no permanent change may be necessary.

2. Restart and update Windows security

Restart Windows, install pending Windows updates, and update Microsoft Defender security intelligence through Windows Security. Do not download replacement Defender executables, DLL files, or drivers from third-party download sites.

3. Review Windows Security

In current Windows 10 and Windows 11 wording, open Windows Security > Virus & threat protection. Review:

Rank #3
Sale
McAfee Total Protection 2027 Antivirus Software for 5 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
  • Current threats and Protection history.
  • The state of Real-time protection.
  • Security-intelligence update status.
  • Configured Exclusions.
  • Warnings that protection is disabled or controlled by an organization.

The exact screen can differ across Windows 10, Windows 11, Windows Server, and managed enterprise devices. A third-party antivirus product or organizational policy may control settings that are unavailable locally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Use Defender’s performance analyzer

For a persistent Defender-related performance problem, Microsoft provides a performance analyzer that records scan activity and identifies files, paths, extensions, and processes associated with the greatest scanning impact. Run PowerShell as Administrator and start a recording:

New-MpPerformanceRecording -RecordTo "$env:USERPROFILEDesktopDefender-scans.etl"

Reproduce the slowdown while the recording runs. Press Enter in the recording window to stop and save the ETL file. Then analyze the recording:

Get-MpPerformanceReport `
  -Path "$env:USERPROFILEDesktopDefender-scans.etl" `
  -TopFiles 10 `
  -TopProcesses 10 `
  -TopScans 10 `
  -Overview

Microsoft says the recording command requires elevated privileges. The performance analyzer is supported on Windows 10 and later and is available from Defender platform version 4.18.2108.X and later. Microsoft also cautions that the analyzer is a diagnostic tool, not an automatic recommendation engine for exclusions. See Microsoft’s performance-analyzer reference and Defender performance-tuning guidance.

5. Add an exclusion only after diagnosis

If the analyzer identifies a trusted, high-churn directory as the cause, an administrator may consider a narrowly scoped exclusion. An exclusion can reduce scanning overhead, but it also removes or reduces a security inspection for the excluded content.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Exclusion type Effect Main risk
File or folder Reduces Defender scanning for the specified content. Malware placed in or generated within the excluded location may evade inspection.
Process Can affect files opened by the specified process. A compromised process may gain a wider path around scanning.
Broad system or drive exclusion Reduces protection across a large area. Creates an unnecessarily large blind spot and should not be used as routine performance tuning.

Use a full path and filename when excluding a process where possible. Microsoft recommends narrowly scoped exclusions and warns that exclusions increase security risk in its Windows Security protection guidance.

Do not exclude an entire drive, user-profile root, Downloads folder, or arbitrary system directory merely to reduce CPU usage. First identify the actual workload and confirm that the files and software are trusted.

How can you inspect the WdNisSvc service?

Use the following PowerShell command to check the basic service state:

Get-Service -Name WdNisSvc

For the display name, state, startup mode, and configured executable path, run:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Norton 360 Deluxe 2027 Antivirus, 3 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
Get-CimInstance Win32_Service -Filter "Name='WdNisSvc'" |
    Select-Object Name, DisplayName, State, StartMode, PathName
Result What it means
Running The service is currently active.
Stopped Not automatically an error; Defender state, demand-start behavior, policy, or another antivirus can affect the state.
Disabled Worth investigating if Microsoft Defender is expected to protect the device.
Missing service, invalid path, or unsigned executable More concerning and should be investigated with Windows Security, a scan, and appropriate support.

Do not assume that the service must have one universal startup type on every Windows edition and build. Windows client, Windows Server, enterprise policy, and third-party security configurations can change how Defender components are started.

Should you stop, disable, or delete NisSrv.exe?

Usually, no. Ending or disabling NisSrv.exe can remove or reduce part of Microsoft Defender’s protection, and the change may not be durable. Windows security settings, Defender updates, organizational policy, or a restart can restore the service state.

Do not delete NisSrv.exe, forcibly take ownership of Defender folders, use registry hacks, or run scripts that remove Defender components as routine troubleshooting. Those actions can damage Windows security and make later diagnosis or repair harder.

If you temporarily turn off real-time protection for a controlled diagnostic test, remember that files opened or downloaded while protection is off may not receive real-time scanning. Microsoft may automatically restore the setting after a short period, and turning off real-time protection does not necessarily disable every Defender feature or scan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What if a third-party antivirus is installed?

A compatible non-Microsoft antivirus product can cause Microsoft Defender Antivirus to turn itself off automatically, according to Microsoft’s Windows Security guidance. The mere presence of an antivirus application does not prove that it is correctly registered or controlling real-time protection.

Check Windows Security to identify which product is active before changing Defender services. Do not intentionally run two competing real-time antivirus products at the same time. On a managed computer, compatibility, Intune or Group Policy, and endpoint-security policy may determine which service is enabled.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if NisSrv.exe looks suspicious?

Treat the executable as suspicious if it is outside a credible Defender directory, lacks a valid Microsoft signature, has an invalid signature, triggers a Windows Security detection, or repeatedly appears as an unrelated duplicate process.

  1. Do not open or execute the suspicious file.
  2. Record its location and signature details.
  3. Run a full scan from Windows Security > Virus & threat protection.
  4. If malware is suspected or Defender cannot operate normally, use Microsoft Defender Offline from Windows Security.
  5. Review Protection history and relevant Defender or Windows event logs.
  6. On a business-managed device, contact the organization’s IT or security team rather than deleting the file.

A low CPU reading does not prove that a file is legitimate, and a high CPU reading does not prove that a file is malicious. Authentication, detections, file location, and the broader security state provide better evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What if NisSrv.exe cannot start or keeps stopping?

A service that stops is not automatically evidence of corruption because Defender components can be controlled by security state, policy, demand-start behavior, Windows edition, or another antivirus. Repeated failure combined with Windows Security warnings does require troubleshooting.

Best Value
Sale
Norton 360 Deluxe 2027 Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
  1. Check Windows Security > Virus & threat protection for protection errors.
  2. Install pending Windows and Defender updates.
  3. Restart the computer.
  4. Review Defender-related operational logs in Event Viewer.
  5. Run a full scan, followed by Microsoft Defender Offline if malware is suspected.
  6. Repair Windows system files if other corruption symptoms are present.
  7. On an enterprise device, check Intune, Group Policy, Microsoft Defender for Endpoint, and other endpoint-security software.
  8. Escalate with the relevant error code and Defender logs if the service repeatedly fails.

Commands such as net start or sc may be useful to administrators in a specific diagnostic case, but restarting the service is not a universal repair. The correct action depends on the error, policy, and security product controlling the device.

Does Windows Server need NisSrv.exe?

Windows Server configuration requires more caution than a typical home PC. Defender settings, server roles, throughput requirements, endpoint-management policy, and workload sensitivity can differ substantially from Windows 10 or Windows 11.

Microsoft has published guidance describing Network Inspection System behavior and cautioning that network inspection may be unsuitable for some high-throughput server roles. That historical server guidance should be applied to the specific server role and current Microsoft documentation, not generalized to every Windows Server installation; see Microsoft’s Network Inspection System background and server guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not apply a consumer-PC exclusion or disablement procedure to a domain controller, SQL Server, Exchange Server, file server, or managed endpoint without checking the applicable Microsoft and organizational guidance.

What is the safest decision for your situation?

What you observe Recommended action
NisSrv.exe appears briefly or uses modest resources. Leave it alone; this is usually ordinary Defender activity.
Usage rises during a scan, update, extraction, build, or installation. Let the operation finish and reassess afterward.
Usage remains high after a restart and normal activity. Update Defender, review Windows Security, and use the performance analyzer.
The process is unsigned or in an unrelated directory. Treat it as suspicious, scan it, and investigate instead of assuming it is Microsoft’s file.
Windows Security reports protection errors. Investigate Defender repair, updates, policy, and third-party security software.
The device is a server or managed enterprise endpoint. Check server-role guidance and organizational policy before changing local settings.

Frequently Asked Questions

Is NisSrv.exe a virus?

NisSrv.exe is normally a legitimate Microsoft Defender Antivirus component, not a virus, when it has a valid Microsoft digital signature and is located with the Defender installation. A copied filename can still be malicious, so verify the signature, location, and Windows Security results.

Can I end or disable Microsoft Network Realtime Inspection Service?

You generally should not end, disable, or delete Microsoft Network Realtime Inspection Service to solve ordinary resource usage because doing so reduces Defender protection and may not be permanent. Diagnose persistent usage first with Windows Security and Defender’s performance analyzer.

Why does NisSrv.exe use CPU after I install software or extract an archive?

NisSrv.exe may use CPU while Microsoft Defender inspects files created, opened, or executed during software installation or archive extraction. If usage drops when the operation ends, the activity may be normal; persistent usage requires further diagnosis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does installing another antivirus always stop NisSrv.exe?

No. Microsoft says a compatible non-Microsoft antivirus can cause Defender Antivirus to turn itself off automatically, but registration and behavior vary by product, Windows edition, and policy. Check Windows Security to identify which antivirus is active.

What does a stopped WdNisSvc service mean?

A stopped WdNisSvc service is not automatically an error because Defender components can be demand-started or controlled by Defender state, policy, Windows edition, or another antivirus. A missing service, invalid executable path, unsigned file, or Windows Security protection error is more concerning.

The Bottom Line

Bottom line: Microsoft Network Realtime Inspection Service (NisSrv.exe) is normally a legitimate Microsoft Defender Antivirus component. Leave it enabled when the executable is Microsoft-signed and Defender is operating normally. If resource usage remains high, diagnose the workload with Windows Security and Defender’s performance analyzer; use exclusions only when the cause is understood and the exclusion can be narrowly scoped.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.