MsMpEng.exe

by Microsoft
Endpoint Security

Sources: 300M+ executions observed in the wild.

Summary

Microsoft Malware Protection Engine - core antimalware scanning engine for Windows Defender / Microsoft Defender Antivirus.

MsMpEng.exe is the 557th most commonly executed Windows program in EchoTrail's dataset, observed 8,981 times across enterprise environments. It typically runs from C:\ProgramData\... and it is most often launched by services.exe.

Get this in your tools

The same record for msmpeng.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/msmpeng.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

557th
most commonly executed Windows program
8,981
observed endpoint executions

Behavior

Top Paths

  • C:\ProgramData\...89.71%
  • C:\Program Files\Windows Defender10.09%
  • C:\Program Files\Microsoft Security Client0.2%

Top Hashes (SHA256)

  • 641bcd04d2ec651a4612fc37e2487cb93ed1998baaac2a14031515ee292c893e5.33%
  • e00c7bf4529b4eb434aa7086cbcabe6ad08ace765e0c6ec8225282378989e2f35.08%
  • bcbaa0796c601bdfc4829add08ef34609291bd424eef526a07960dd6b66b94c93.49%
  • de0dc4f2e623a2f3ab5f57010765954a77e52d995af74f6d8a52841c941c041b3.23%
  • 4fbe52aec27f8e0fb97d6c40c0c90787de53bda499a05cdc1e94be691055c2c63.1%
  • 9c47bcedf290cc9915b65fa26c11cf2940bb5addd03dcbdccef91e4a45c2289e2.82%
  • 2ff320449da555d46807013f241dcf3d3a68f3ba2b692686479b8b32504f42d82.71%
  • cf0902fe24ce006ccaa9675928bea6d0920b11d584012c298ff1e5b6b2ab972a2.58%
  • 2ccb6063389f3512be2ef169e236c7474380c542abd82b4b6bcaa8dee2e3dcbe2.29%
  • 4c50cb2656c0883129011505b21dfb7bb85cc6652399d3ddeccb66ce9f319af52.27%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does MsMpEng.exe normally do?

Runs as the core scanning process for Windows Defender. High CPU during active scans is expected. Runs as SYSTEM from %ProgramFiles%\Windows Defender\MsMpEng.exe.

When is MsMpEng.exe suspicious?

Not running when Defender should be active. Running from a path other than the Windows Defender directory. Crashing repeatedly.

How do attackers abuse MsMpEng.exe?

Attackers attempt to disable or tamper with MsMpEng.exe. Some exploits have targeted the Defender engine itself (CVE-2017-0290 allowed remote code execution via crafted files scanned by the engine).

Detection guidance

Monitor for Defender service stops (Event ID 5001). Alert on Defender exclusion additions (Event ID 5007). Detect attempts to tamper with Defender via PowerShell Set-MpPreference.

False positive notes

High CPU during scheduled scans is normal. Temporary service restarts during definition updates are expected.

Related Processes

Ask Rocky about MsMpEng.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for MsMpEng.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.