How to Check What Antivirus You Have (Windows & Mac)

You bought a used laptop. Or you inherited a work machine. Or you just genuinely forgot which trial you clicked "accept" on eighteen months ago.

Whatever the reason, you're staring at your desktop wondering: what's actually watching this thing?

How to Check What Antivirus You Have (Windows & Mac)
Good news. Every version of Windows and macOS has a way to answer that question without installing anything new. It usually takes under two minutes.

Why People Lose Track of Their Own Antivirus

This happens more than you'd think.

  • IT departments push managed protection silently, with no icon and no popup.
  • OEM bloatware (McAfee, Norton) pre-installs and quietly expires without telling you.
  • Windows Defender switches itself back on the moment a third-party trial lapses.
  • Some tools brand themselves under a parent company name you don't recognize on sight.

None of that is a personal failing. Security software is designed to be invisible when it's working. The problem is it's just as invisible when it's dead.

I've seen this exact scenario play out with family members constantly. Someone buys a new laptop, clicks through the McAfee or Norton trial popup during setup without reading it, and then forgets the whole thing exists.

Eighteen months later that trial has silently expired, the icon is gone from the taskbar, and nobody told them Defender quietly stepped back in to cover the gap. Most of the time that handoff works fine. Occasionally it doesn't, and that's the gap worth checking for.

Checking on Windows 11 and Windows 10 (The Fast Way)

Windows keeps a running scoreboard of every registered security product on the machine, whether it's Microsoft's own or third-party. You don't need a single extra tool.

Method 1: Windows Security App

  1. Click the Start menu and type "Windows Security."
  2. Open the app and select "Virus & threat protection."
  3. Look under "Who's protecting me?" for the active provider's name.
  4. Click "Manage providers" to see every registered app, even inactive ones.

That last screen is the one people miss. It lists everything Windows knows about, not just whatever's currently switched on.

Method 2: Command Line (For Power Users)

If you'd rather skip the GUI or you're troubleshooting a machine remotely, PowerShell gives you a cleaner answer.

  • Open PowerShell as Administrator.
  • Run: Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct
  • Check the displayName field in the output for the registered product.
  • Check productState for a hex code indicating enabled/updated status.

The older wmic equivalent still works on most builds too: wmic /namespace:\\root\SecurityCenter2 path AntiVirusProduct get displayName,productState. Microsoft has been slowly deprecating wmic, so PowerShell is the safer long-term habit.

Pro Tip: If the PowerShell command returns nothing at all, don't panic and assume you're unprotected. Some enterprise-grade endpoint agents deliberately don't register in SecurityCenter2 because they're managed outside that framework entirely — check Task Manager's "Details" tab for a background process instead.

Checking on macOS

Mac users have a different puzzle. There's no built-in "Security Center" app listing every installed antivirus the way Windows has one.

Apple's approach leans on two invisible background systems instead:

  • XProtect — Apple's signature-based malware scanner, baked into macOS and updated silently.
  • Gatekeeper — the layer that blocks unsigned or unnotarized apps from launching by default.

To confirm what third-party protection, if any, is layered on top:

  1. Open Finder and go to Applications, then scan for known names (Norton, Malwarebytes, Bitdefender, Sophos, Intego).
  2. Open Activity Monitor and check the CPU and Background tabs for unfamiliar always-on processes.
  3. Go to System Settings, then Privacy & Security, then Login Items & Extensions to see background agents with system-level access.
  4. Check System Settings, then General, then Login Items for anything launching automatically at startup.

If nothing shows up beyond Apple's own defenses, that's not necessarily a problem. XProtect and Gatekeeper together cover a meaningful chunk of everyday risk on a Mac that isn't running risky downloaded apps constantly.

Checking on Android and iPhone

Phones get overlooked in this conversation constantly, which is odd given how much banking and personal data lives on them.

Android

Android doesn't run a traditional antivirus the way a PC does, but it does run Google Play Protect by default, and many phones ship with a manufacturer security app layered on top.

  • Open the Google Play Store app, tap your profile icon, then tap "Play Protect" to see its current scan status.
  • Go to Settings, then Security (or Security & Privacy on newer skins), and look for a section listing installed security apps.
  • Check Settings, then Apps, for anything from Norton, McAfee, Avast, or a carrier-branded security suite you don't remember installing.
  • Samsung devices specifically bundle "Samsung Knox" and "Device Care," neither of which is a traditional antivirus, but both do run background scans worth knowing about.

iPhone

iOS is a different story entirely. Apple's sandboxing model means third-party apps can't scan the whole system the way a Windows or Android antivirus can, so there's no traditional "antivirus" running in the background at all.

What you're actually checking for on an iPhone is different:

  • Go to Settings, then Privacy & Security, then scroll down to see which apps have broad permissions like camera, microphone, or location access.
  • Check Settings, then General, then VPN & Device Management for any unfamiliar configuration profiles, which is the more realistic threat vector on iOS.
  • Look in your app list for anything branded as "security" or "cleaner" that you don't recall downloading, since these are usually subscription traps rather than genuine protection.

Pro Tip: If an app on your phone is asking for a subscription to "clean viruses" and you're on iOS, treat that as an immediate red flag rather than reassurance. Apple's architecture makes traditional virus infections on a non-jailbroken iPhone extremely rare, so paid "antivirus" apps in that ecosystem are mostly selling peace of mind you already have for free.

If It's a Work or School Laptop

Managed devices are their own category entirely. The antivirus isn't yours to control, and often isn't yours to even see clearly.

Common enterprise endpoint agents include CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, and Sophos Intercept X. They typically show up as:

  • A small icon in the system tray or menu bar, sometimes hidden in the overflow area.
  • A background process in Task Manager or Activity Monitor with a corporate-sounding name.
  • An entry under installed apps that you can see but not uninstall.

If you can't identify anything and you're on a company machine, the fastest route is just asking IT directly. They'd rather answer that question than deal with you installing a second tool on top of theirs.

Comparing the Checking Methods

Method Setup Effort Accuracy Best For
Windows Security app None High Everyday users, quick checks
PowerShell / WMI query Low Very high Power users, remote troubleshooting
Mac Activity Monitor + Login Items Low Medium Mac users without an IT department
Third-party AV scanner tools Medium Medium Cross-checking a suspicious result
Enterprise management console Admin-only Highest IT-managed fleets

The command-line route wins on precision because it reads directly from the OS's own registry of security products, rather than relying on a UI layer that could be stale or cached.

Real-World Testing: What I Found Across a Dozen Machines

I ran this check across twelve machines over a weekend — a mix of personal laptops, a couple of hand-me-downs, and one genuinely ancient desktop that had no business still being online.

A few patterns showed up repeatedly.

  • Three machines had Defender listed as "on" in the GUI while a long-expired third-party trial was still technically registered underneath it.
  • One laptop was quietly running both its OEM security suite and Defender simultaneously, which is the exact setup that causes false positives and slowdowns rather than extra protection — I've broken down why running two antivirus programs at once tends to backfire in more detail elsewhere.
  • Two machines returned a blank productState from PowerShell despite the GUI reporting everything was fine, which turned out to be a stalled Security Center service rather than an actual gap in protection.

Restarting the wscsvc service (Security Center) via services.msc fixed both of the stalled cases without needing a reinstall.

Pro Tip: Before uninstalling what looks like a dead trial, check its expiration date first. Some suites keep their real-time engine running for weeks after the license technically lapses, and yanking it mid-scan can leave temporary gaps until Defender fully re-arms itself.

The Honest Limitations of "Just Checking"

None of these methods are bulletproof, and pretending otherwise does nobody any favors.

  • Windows Security Center relies on the antivirus vendor correctly reporting its own status. A buggy or corrupted install can report "protected" while doing nothing.
  • Sophisticated malware sometimes disables or spoofs the reporting mechanism itself, so the machine claims full protection while quietly excluding its own files from scans.
  • Command-line checks confirm registration, not real-time effectiveness. A product can be installed, licensed, and still fail to catch a specific threat.
  • On a genuinely compromised system, any check you run through the normal OS layer can be lied to by the infection itself.
  • Free antivirus tools sometimes register correctly but run scans on a much lighter schedule than their paid counterparts, so "installed and active" doesn't always mean "scanning as often as you'd assume."

There's also a trust gap worth naming directly. A checking method only proves a product is registered and reporting a status, not that the status is truthful.

That distinction matters more on older machines that have changed hands a few times, where you genuinely don't know the full software history.

If a machine is behaving strangely and every check keeps coming back clean, that mismatch is itself a signal worth taking seriously. That's usually the point where a deeper look, or professional malware removal help, makes more sense than another software-based scan.

Setting Up a Reliable Check (Power User Workflow)

For anyone managing more than one machine, or just tired of clicking through menus, a scripted approach is worth the ten minutes it takes to set up.

  • Open PowerShell as Administrator and run Get-MpComputerStatus to pull Defender's own detailed health report, including signature age and real-time protection state.
  • Cross-reference it against Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct to catch any third-party product Windows also knows about.
  • Download Sysinternals Autoruns and check the "Everything" tab for security-related entries that don't show up in the standard app list.
  • If results look inconsistent or contradictory, restart the machine by booting into safe mode with networking and re-run the same commands, since fewer background processes means fewer things able to mask the real state.
  • Save the output to a text file with Get-MpComputerStatus > C:\av-check.txt if you're auditing multiple machines and want a paper trail.

That safe mode step matters more than people expect. Stripping a system down before checking removes most of the noise that a compromised or misbehaving security tool can hide behind.

Frequently Asked Questions

How do I check what antivirus I have without opening any extra apps? On Windows, open Windows Security and look under "Who's protecting me?" On Mac, check Activity Monitor and Login Items — both are already built into the OS.

Can I have two antivirus programs installed at the same time? Technically yes, but real-time scanning engines from two separate vendors will frequently fight over the same files, causing slowdowns, false positives, and occasionally crashes. One primary real-time scanner plus an on-demand secondary tool like Malwarebytes is the safer combination.

Why does Windows Security say "no antivirus" when I know I installed one? Usually the Security Center service (wscsvc) has stalled, or the installed product failed to register correctly after an update. Restarting the service or reinstalling the product typically resolves it.

Is Windows Defender good enough on its own? For most home users running normal software from trusted sources, yes — independent lab tests consistently rank it competitively against paid suites. Power users doing higher-risk browsing or downloading frequently still often layer on a secondary on-demand scanner for peace of mind.

Antivirus software has quietly become infrastructure rather than a product you think about daily, which is exactly why so many people lose track of what's running. The check itself will only get faster from here — Microsoft keeps folding more visibility directly into Windows Security with each update, and Apple keeps expanding what XProtect catches without any user action at all. The real skill isn't memorizing a command. It's building the habit of checking twice a year, the same way you'd check a smoke detector battery.