Network Protection Events in Event Viewer

The Windows 10 Event Viewer can be used to query Windows Defender Exploit Guard Network Protection (Network Protection) activity. This illustration shows the Windows 10 Event Viewer on a device with Network Protection enabled in audit mode.

The 5007 events are general entries written to the log when a change is made to Network Protection’s configuration. The 1125 entries detail an attempt to connect to a malicious site. (In this case, a Microsoft-managed test site is intentionally marked as a malicious site.)

