For everyone implementing Microsoft Windows Defender Antivirus, here's a quick note where to find the client logs and how to use them:
- C:\ProgramData\Microsoft\Windows Defender\Support
- MPLog-######-#####.log
- MPDetection-######-#####.log
- MPCacheStats.log (Defender Only)
You should use the MPLog to:
- Search Threat Name to locate a record of malware detection.
- Search Scan Source to locate a record of a scheduled scan running or record a running scan that is on demand.
- Search Expensive file to locate an instance of an expensive file detection during a scan.
- Seach on update process