MpDefenderCoreService.exe

by RealDefense LLC

Sources: observed in the EchoTrail lab on Windows 11.

Summary

Antimalware Core Service (Microsoft® Windows® Operating System, Microsoft Corporation)

MpDefenderCoreService.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-29 installed from winget package Microsoft.WindowsSDK.10.0.22621.

Get this in your tools

The same record for mpdefendercoreservice.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/mpdefendercoreservice.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

3344th
most commonly executed Windows program
n/a
observed endpoint executions

Behavior

Top Paths

  • C:\ProgramData\...100%
  • C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26080.4-0

Top Hashes (SHA256)

  • 3b6bf984e0407aa79250f6ea639175975cc47b83077fe3c66c28aa2a44d90fbf15.15%
  • 1308a3ce235a7d3d5c67c4d07a181f71b12a00ff7ff8f46ade593478518e22e712.12%
  • c740605823b78731649f8ed3dc098b29f32f949da04a9245e6ec298f32d8c48e12.12%
  • a0a798830f92ff3daa6719aa38d62abd2e221d9256d5179063e8d4dab6b9078e9.09%
  • b341d1ebb1413d5985e4b2e87bdba4a4aae7c1fff85ec2ccb6ea948f40fffa9d9.09%
  • 08f00ebd436caddbbc6aa8fa4bdfe4fc95ca8ebe55ef20ae1cc24a123a185ac57.58%
  • 21573e7fa71d88cd123da1fd9563d75b6f9222f7419c2fb3e5fc0577160e06017.58%
  • 908b69bfc76ee814cfe65088125b3fad86ac5d03ee9e4935edb0beb748b925667.58%
  • c26bb7de89d5cc31c99d2a6df0e5ebe655e30bb424061a6d794b7acaa12de6df6.06%
  • 1f2fc67c57e3e0dc0a65ea2bca5a431f819265971e643537f418ed2c1ad4eecc4.55%
  • e185fe0598e3b23fa5b4a76b06e1983609857537849cb1ecef2f408bf41f06f6

Process Ancestry

Top Parents

Lab record

Installed from
winget Microsoft.WindowsSDK.10.0.22621 10.0.22621.2428
Publisher
Microsoft Windows Publisher
Persistence
none
Network
11 destinations
Command lines
1 pattern (10 launches)
DLL loads
71 patterns (716 loads)
Registry writes
25 patterns (566 writes)
File writes
2 patterns (20 writes)
HTTP requests
0 patterns (0 requests)
TLS connections
3 patterns (16 handshakes)
Named pipes
0 patterns (0 events)
Process access
0 patterns (0 events)
Driver loads
12 patterns (12 loads)
PowerShell blocks
0 patterns (0 blocks)
Remote threads
0 patterns (0 events)
Audit events
0 patterns (0 events)

Full record on Team.

Ask Rocky about MpDefenderCoreService.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for MpDefenderCoreService.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.