Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To test Microsoft Defender SmartScreen, use Microsoft’s safe demonstrations for app and URL reputation. To test Microsoft Defender Antivirus, use the harmless EICAR test file. They exercise different protection layers: an EICAR detection does not show that SmartScreen works, and a SmartScreen warning is not necessarily an antivirus detection.
For broader checks, Microsoft Defender Testground and AMTSO offer benign scenarios for potentially unwanted apps, phishing, compressed files, and cloud lookups. Use the steps below to identify what responded and where to confirm the result.
What each test checks
| Protection | What it evaluates | Appropriate test |
|---|---|---|
| SmartScreen URL reputation | Whether a site or URL is associated with phishing or other unsafe content | Microsoft Defender Testground URL reputation demonstration |
| SmartScreen app and download reputation | Reputation signals for downloaded files and publishers | Microsoft’s known-good, unknown, and known-malware app-reputation demonstrations |
| Microsoft Defender Antivirus | File content and antivirus detection handling | EICAR test file |
| Potentially unwanted app (PUA) protection | Blocking apps classified as potentially unwanted, rather than necessarily malware | Microsoft Defender Testground PUA demonstration or AMTSO PUA test |
| Cloud lookup and other security features | Specific online or feature-check paths | Relevant AMTSO Security Features Check |
| Smart App Control | Whether Windows permits untrusted or unsafe executable code | Its separate Windows 11 testing guidance—not an EICAR or SmartScreen test |
SmartScreen uses reputation signals for websites and downloads; Defender Antivirus is the antimalware engine. A warning that a file is unrecognized is not the same as a confirmed malware verdict. See Microsoft’s SmartScreen overview and Windows security overview.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Prepare a safe test environment
- Use a disposable test device or virtual machine if practical, and save your work before intentionally triggering a detection.
- Use only the demonstrations and test files described here. Do not download or execute live malware.
- For an antivirus test, ensure real-time protection is enabled. If validating Defender for Endpoint, confirm the device is onboarded and reporting.
- Record the Windows edition and build, browser version, Defender security-intelligence version, relevant settings, and any management policies or exclusions.
- On a work or school device, Group Policy, Intune, or another MDM policy may override local controls. Do not try to bypass your organization’s settings.
Microsoft documents EICAR as a way to validate antimalware detection. The Windows Security interface and available controls can vary by Windows release, language, edition, and management state.
#1 Best Overall
Check the protection settings
- Open Windows Security and select App & browser control.
- Open Reputation-based protection. Check the status of Check apps and files, SmartScreen for Microsoft Edge, and potentially unwanted app blocking, where shown.
- Return to Windows Security, open Virus & threat protection, then select Manage settings. Check Real-time protection; check Cloud-delivered protection if it is relevant to your test.
If a control is missing or greyed out, that alone does not prove the protection is off: an administrator may manage it centrally. Microsoft’s App & browser control guide and SmartScreen settings documentation explain the available controls and policy configuration.
Test SmartScreen app reputation
Use Microsoft’s application-reputation demonstration, described in the Microsoft Defender app-reputation demo documentation. Run the scenarios one at a time in Microsoft Edge:
- Known good: the demonstration should proceed without a SmartScreen interruption.
- Unknown: expect an unrecognized or unknown-file reputation warning, with a deliberate decision required.
- Known malware: expect SmartScreen to block the download or prevent the relevant action.
Record the exact warning and whether Edge blocked a download, Windows Security reported a detection, or another control intervened. A browser warning can reflect reputation rather than an antivirus verdict. A block could also come from Defender Antivirus, Smart App Control, Network Protection, a web gateway, or an enterprise policy; check the reporting surface before attributing it to SmartScreen.
Free tools Windows power users keep installed
One-click scans. No signup required.
Test SmartScreen URL reputation
Open Microsoft Defender Testground in Edge and use its URL-reputation demonstration for phishing or malware-site scenarios. Run each available safe scenario separately. Note whether Edge shows an unsafe-site warning, blocks navigation, allows the page, or the request is stopped elsewhere.
A SmartScreen warning page is different from a DNS-filter, proxy, firewall, or secure-web-gateway block. URL results can be affected by Edge policy, Defender Network Protection, DNS filtering, proxy inspection, browser extensions, and corporate allow/block lists. If the result does not resemble a browser warning, check those controls before concluding that SmartScreen responded.
Test Defender Antivirus with EICAR
EICAR is a harmless standard antivirus test string intentionally recognized by security products. Do not treat it as real malware, and expect Defender to quarantine or remove it. Microsoft’s full procedure is in its antimalware validation guidance.
- In a plain-text editor, enter this exact single-line string:
X5O!P%@AP[4PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
- Save the file as
EICAR.txtin a normal, non-excluded folder. - Open Command Prompt in that folder and run
type EICAR.txt. - Check Windows Security > Virus & threat protection > Protection history for a detection, quarantine, or removal. If the device is managed, also check its Defender for Endpoint record where applicable.
Defender may detect the file as it is created or accessed, so it may disappear before the command can display it. That is normally a successful response; look in Protection history rather than repeatedly trying to open or restore it.
Recommended Free Tools
Create the test file locally with PowerShell
Microsoft also documents writing the EICAR content to a local file. In PowerShell, run:
$eicar = 'X5O!P%@AP[4PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*'
[IO.File]::WriteAllText("$env:TEMPEICAR.txt", $eicar)
The file may be detected immediately. Microsoft documents EICAR and exclusion testing in its Defender Antivirus exclusions guidance. Use one method, not several, unless you have a specific validation need.
Validate an exclusion carefully
EICAR can help check file, folder, filename, or extension exclusions because detection is based on the test content, not just its name. Microsoft’s guidance supports testing those exclusion types; this does not validate a process exclusion by itself, because that depends on the process that opens the file.
| Test | What it can tell you |
|---|---|
| EICAR in a normal folder | Baseline detection outside the exclusion |
| EICAR in the excluded folder | Whether the folder exclusion appears to apply |
| EICAR with an excluded filename or extension | Whether that matching exclusion appears to apply |
| EICAR outside the exclusion after the excluded-path test | Whether detection remains active elsewhere |
| EICAR opened by a process covered by a process exclusion | Requires testing the process path specifically; a file test alone is insufficient |
Interpret results only in the context of the exact policy and path tested. Remove any temporary exclusions immediately after testing; exclusions leave a protection gap.
Test PUA protection and other features
Microsoft’s PUA demonstration is intended to check whether potentially unwanted app protection blocks a benign test from downloading or installing. Depending on settings and management policy, the test may be blocked at download, quarantined, stopped at execution, or logged without a visible prompt. Some configurations distinguish Block apps from Block downloads; note which setting and event your result represents.
For additional benign checks, use the AMTSO Security Features Check. Its scenarios include manually downloaded malware test items, PUA, compressed files, drive-by downloads, phishing pages, and cloud-based lookups. Do not label every AMTSO result a SmartScreen test. A browser warning, file quarantine, PUA alert, or cloud lookup result exercises different paths, and a third-party product or network control may be responsible.
Test Smart App Control separately
Smart App Control is distinct from SmartScreen and Microsoft Defender Antivirus. Microsoft Support says it is a Windows 11 feature available only under specific new-installation or reset conditions; it is not available in Windows 10. For developer or administrator testing, follow Microsoft’s separate Smart App Control testing guidance, including its instructions for evaluation, policy, and event review.
If an application is blocked, check the Smart App Control status and relevant event records before calling it a SmartScreen block. Smart App Control can affect app behavior on some Windows 11 systems; an EICAR result does not test it.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Interpret results and troubleshoot
| Scenario | Expected response | Where to check |
|---|---|---|
| Known-good app demo | Proceeds without a SmartScreen interruption | Edge download history; Windows Security if an alert appears |
| Unknown app demo | Reputation warning or confirmation prompt | Edge download panel and warning; policy settings |
| Known-malware app demo | Download or action blocked | Edge, Windows Security, and managed-device telemetry if applicable |
| EICAR | Detection, quarantine, or removal | Protection history; Defender for Endpoint record if applicable |
| PUA or AMTSO test | Block, quarantine, warning, or a feature-specific result depending on configuration | Browser status, Protection history, and relevant security logs |
SmartScreen demo produces no warning
Confirm you used the intended demo in Edge and check the relevant reputation settings and applied policy. A proxy, DNS filter, gateway, or network issue may have changed the request; another control may also have generated the result. Microsoft’s Edge SmartScreen documentation describes its behavior and management.
Best Value
- Comes with secure packaging
- It can be a gift item
- Easy to read text
EICAR is not detected
- Confirm real-time protection is on and the string was copied exactly, without extra characters or an encoding change.
- Check whether another antivirus is registered as primary, or Defender is in a passive or disabled state.
- Check whether the test path is covered by an exclusion or managed policy.
- For a managed endpoint, distinguish local detection from reporting: check onboarding and the endpoint record as well as Protection history.
Microsoft notes that Defender identifies EICAR by content, not by filename. A missing visible alert alone does not establish that no event was recorded.
A safe or signed app gets a SmartScreen warning
An unknown-reputation warning does not necessarily mean the app is malicious. SmartScreen considers publisher and file reputation; a new binary can still be unfamiliar even when signed. Signing does not guarantee a warning-free download, and Microsoft does not publish a universal reputation threshold. See Microsoft’s SmartScreen reputation guidance for developers. Some warnings can be bypassed by users, while enterprise policy may prevent bypass; do not choose “Run anyway” simply to make a test pass.
Record evidence and clean up
For each scenario, record the date and time, Windows edition/build, browser and version, Defender intelligence version, enabled settings, exact test URL or filename, visible warning, whether the file was downloaded or quarantined, Protection history entry, relevant portal event, policy or exclusion, and network conditions. Useful basic checks include:
winver
Get-MpComputerStatus |
Select-Object AMServiceEnabled,
AntivirusEnabled,
RealTimeProtectionEnabled,
IoavProtectionEnabled,
NISEnabled,
IsTamperProtected
Available fields and permissions vary by Windows version and device configuration; do not assume every field is present. After testing, confirm the file was quarantined or removed, delete any remaining copy without restoring it, remove temporary exclusions, and restore any settings you changed. A single successful test validates only the path it exercised—not the entire endpoint security stack.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

