MsMpEng.exe
Summary
Microsoft Malware Protection Engine - core antimalware scanning engine for Windows Defender / Microsoft Defender Antivirus.
MsMpEng.exe is the 557th most commonly executed Windows program in EchoTrail's dataset, observed 8,981 times across enterprise environments. It typically runs from C:\ProgramData\... and it is most often launched by services.exe.
Behavior
Top Paths
- C:\ProgramData\...89.71%
- C:\Program Files\Windows Defender10.09%
- C:\Program Files\Microsoft Security Client0.2%
Top Hashes (SHA256)
- 641bcd04d2ec651a4612fc37e2487cb93ed1998baaac2a14031515ee292c893e5.33%
- e00c7bf4529b4eb434aa7086cbcabe6ad08ace765e0c6ec8225282378989e2f35.08%
- bcbaa0796c601bdfc4829add08ef34609291bd424eef526a07960dd6b66b94c93.49%
- de0dc4f2e623a2f3ab5f57010765954a77e52d995af74f6d8a52841c941c041b3.23%
- 4fbe52aec27f8e0fb97d6c40c0c90787de53bda499a05cdc1e94be691055c2c63.1%
- 9c47bcedf290cc9915b65fa26c11cf2940bb5addd03dcbdccef91e4a45c2289e2.82%
- 2ff320449da555d46807013f241dcf3d3a68f3ba2b692686479b8b32504f42d82.71%
- cf0902fe24ce006ccaa9675928bea6d0920b11d584012c298ff1e5b6b2ab972a2.58%
- 2ccb6063389f3512be2ef169e236c7474380c542abd82b4b6bcaa8dee2e3dcbe2.29%
- 4c50cb2656c0883129011505b21dfb7bb85cc6652399d3ddeccb66ce9f319af52.27%
Process Ancestry
Top Grandparents
- wininit.exe100%
Top Parents
- services.exe97.29%
- cmd.exe2.71%
Top Children
- MpCmdRun.exe72.57%
- svchost.exe11.34%
- wevtutil.exe8.77%
- DismHost.exe6.19%
- mpengine.exe0.55%
- mofcomp.exe0.23%
- taskkill.exe0.23%
- wermgr.exe0.01%
- WerFaultSecure.exe0.01%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does MsMpEng.exe normally do?
Runs as the core scanning process for Windows Defender. High CPU during active scans is expected. Runs as SYSTEM from %ProgramFiles%\Windows Defender\MsMpEng.exe.
When is MsMpEng.exe suspicious?
Not running when Defender should be active. Running from a path other than the Windows Defender directory. Crashing repeatedly.
How do attackers abuse MsMpEng.exe?
Attackers attempt to disable or tamper with MsMpEng.exe. Some exploits have targeted the Defender engine itself (CVE-2017-0290 allowed remote code execution via crafted files scanned by the engine).
Detection guidance
Monitor for Defender service stops (Event ID 5001). Alert on Defender exclusion additions (Event ID 5007). Detect attempts to tamper with Defender via PowerShell Set-MpPreference.
False positive notes
High CPU during scheduled scans is normal. Temporary service restarts during definition updates are expected.
Related Processes
Ask Rocky about MsMpEng.exe
Rocky answers questions about MsMpEng.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.