MpDefenderCoreService.exe
Sources: observed in the EchoTrail lab on Windows 11.
Summary
Antimalware Core Service (Microsoft® Windows® Operating System, Microsoft Corporation)
MpDefenderCoreService.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-29 installed from winget package Microsoft.WindowsSDK.10.0.22621.
Get this in your tools
The same record for mpdefendercoreservice.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/mpdefendercoreservice.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\ProgramData\...100%
- C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0
Top Hashes (SHA256)
- 3b6bf984e0407aa79250f6ea639175975cc47b83077fe3c66c28aa2a44d90fbf15.15%
- 1308a3ce235a7d3d5c67c4d07a181f71b12a00ff7ff8f46ade593478518e22e712.12%
- c740605823b78731649f8ed3dc098b29f32f949da04a9245e6ec298f32d8c48e12.12%
- a0a798830f92ff3daa6719aa38d62abd2e221d9256d5179063e8d4dab6b9078e9.09%
- b341d1ebb1413d5985e4b2e87bdba4a4aae7c1fff85ec2ccb6ea948f40fffa9d9.09%
- 08f00ebd436caddbbc6aa8fa4bdfe4fc95ca8ebe55ef20ae1cc24a123a185ac57.58%
- 21573e7fa71d88cd123da1fd9563d75b6f9222f7419c2fb3e5fc0577160e06017.58%
- 908b69bfc76ee814cfe65088125b3fad86ac5d03ee9e4935edb0beb748b925667.58%
- c26bb7de89d5cc31c99d2a6df0e5ebe655e30bb424061a6d794b7acaa12de6df6.06%
- 1f2fc67c57e3e0dc0a65ea2bca5a431f819265971e643537f418ed2c1ad4eecc4.55%
- e185fe0598e3b23fa5b4a76b06e1983609857537849cb1ecef2f408bf41f06f6
Process Ancestry
Top Parents
- services.exe100%
Lab record
- Installed from
- winget Microsoft.WindowsSDK.10.0.22621 10.0.22621.2428
- Publisher
- Microsoft Windows Publisher
- Persistence
- none
- Network
- 11 destinations
- Command lines
- 1 pattern (10 launches)
- DLL loads
- 71 patterns (716 loads)
- Registry writes
- 25 patterns (566 writes)
- File writes
- 2 patterns (20 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 3 patterns (16 handshakes)
- Named pipes
- 0 patterns (0 events)
- Process access
- 0 patterns (0 events)
- Driver loads
- 12 patterns (12 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 0 patterns (0 events)
Full record on Team.
Ask Rocky about MpDefenderCoreService.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for MpDefenderCoreService.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.