MsMpEng.exe

by Microsoft
Endpoint Security

Summary

Microsoft Malware Protection Engine - core antimalware scanning engine for Windows Defender / Microsoft Defender Antivirus.

MsMpEng.exe is the 557th most commonly executed Windows program in EchoTrail's dataset, observed 8,981 times across enterprise environments. It typically runs from C:\ProgramData\... and it is most often launched by services.exe.

557th
most commonly executed Windows program
8,981
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\ProgramData\...89.71%
  • C:\Program Files\Windows Defender10.09%
  • C:\Program Files\Microsoft Security Client0.2%

Top Hashes (SHA256)

  • 641bcd04d2ec651a4612fc37e2487cb93ed1998baaac2a14031515ee292c893e5.33%
  • e00c7bf4529b4eb434aa7086cbcabe6ad08ace765e0c6ec8225282378989e2f35.08%
  • bcbaa0796c601bdfc4829add08ef34609291bd424eef526a07960dd6b66b94c93.49%
  • de0dc4f2e623a2f3ab5f57010765954a77e52d995af74f6d8a52841c941c041b3.23%
  • 4fbe52aec27f8e0fb97d6c40c0c90787de53bda499a05cdc1e94be691055c2c63.1%
  • 9c47bcedf290cc9915b65fa26c11cf2940bb5addd03dcbdccef91e4a45c2289e2.82%
  • 2ff320449da555d46807013f241dcf3d3a68f3ba2b692686479b8b32504f42d82.71%
  • cf0902fe24ce006ccaa9675928bea6d0920b11d584012c298ff1e5b6b2ab972a2.58%
  • 2ccb6063389f3512be2ef169e236c7474380c542abd82b4b6bcaa8dee2e3dcbe2.29%
  • 4c50cb2656c0883129011505b21dfb7bb85cc6652399d3ddeccb66ce9f319af52.27%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does MsMpEng.exe normally do?

Runs as the core scanning process for Windows Defender. High CPU during active scans is expected. Runs as SYSTEM from %ProgramFiles%\Windows Defender\MsMpEng.exe.

When is MsMpEng.exe suspicious?

Not running when Defender should be active. Running from a path other than the Windows Defender directory. Crashing repeatedly.

How do attackers abuse MsMpEng.exe?

Attackers attempt to disable or tamper with MsMpEng.exe. Some exploits have targeted the Defender engine itself (CVE-2017-0290 allowed remote code execution via crafted files scanned by the engine).

Detection guidance

Monitor for Defender service stops (Event ID 5001). Alert on Defender exclusion additions (Event ID 5007). Detect attempts to tamper with Defender via PowerShell Set-MpPreference.

False positive notes

High CPU during scheduled scans is normal. Temporary service restarts during definition updates are expected.

Related Processes

Ask Rocky about MsMpEng.exe

Rocky answers questions about MsMpEng.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.