Application Error › Event 1000

Event ID 1000 — Faulting application name: Faulting_application_name, version: version, time stamp: 0xFaulting_module_name.

Provider
Application Error
Channel
Application
Level
Error
Collection Priority
Recommended (Microsoft-WEF, others)
Task
ApplicationCrashingEvents

Description

Faulting application name: Faulting_application_name, version: version, time stamp: 0xFaulting_module_name.

Message #

Faulting application name: %1, version: %2, time stamp: 0x%3
Faulting module name: %4, version: %5, time stamp: 0x%6
Exception code: 0x%7
Fault offset: 0x%8
Faulting process id: %9
Faulting application start time: %10
Faulting application path: %11
Faulting module path: %12
Report Id: %13
Faulting package full name: %14
Faulting package-relative application ID: %15

Fields #

NameDescription
Faulting_application_name
version
Faulting_module_name
version
Faulting_application_path
Faulting_module_path
Report_Id
Faulting_package_full_name
Faulting_packagerelative_application_ID

Example Event #

{
  "system": {
    "provider": "Application Error",
    "guid": "",
    "event_source_name": "",
    "event_id": 1000,
    "version": 0,
    "level": 2,
    "task": 100,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-18T20:11:24.000000Z",
    "event_record_id": 1590,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

References #