Microsoft-Windows-AppLocker

49 events across 6 channels

Event IDTitleChannel
8000AppID policy conversion failed.EXE and DLL
8001The AppLocker policy was applied successfully to this computer.EXE and DLL
8002FilePathBuffer was allowed to run.EXE and DLL
8003RuleAndFileData.FilePath was allowed to run but would have been prevented from …EXE and DLL
8004FilePathBuffer was prevented from running.EXE and DLL
8005FilePathBuffer was allowed to run.MSI and Script
8006FilePathBuffer was allowed to run but would have been prevented from running if …MSI and Script
8007FilePathBuffer was prevented from running.MSI and Script
8008FilePathBuffer: AppLocker component not available on this SKU.EXE and DLL
8009FilePathBuffer: AppLocker component not available on this SKU.MSI and Script
8010Operational
8011Operational
8012Operational
8013Operational
8014Operational
8015Operational
8016Operational
8017Operational
8018Operational
8019Operational
8020PackageBuffer was allowed to run.Packaged app-Execution
8021PackageBuffer was allowed to run but would have been prevented from running if …Packaged app-Execution
8022PackageBuffer was prevented from running.Packaged app-Execution
8023PackageBuffer was allowed to be installed.Packaged app-Deployment
8024PackageBuffer was allowed to run but would have been prevented from running if …Packaged app-Deployment
8025PackageBuffer was prevented from running.Packaged app-Deployment
8026No packaged apps can be executed while Exe rules are being enforced and no …Packaged app-Deployment
8027No packaged apps can be executed while Exe rules are being enforced and no …Packaged app-Execution
8028FilePath was allowed to run but would have been prevented if the Config CI …MSI and Script
8029FilePath was prevented from running due to Config CI policy.MSI and Script
8030ManagedInstaller check SUCCEEDED during Appid verification of ImageNameLength.EXE and DLL
8031SmartlockerFilter detected file FileName being written by process …EXE and DLL
8032ManagedInstaller check FAILED during Appid verification of ImageNameLength.EXE and DLL
8033ManagedInstaller check FAILED during Appid verification of ImageNameLength.EXE and DLL
8034ManagedInstaller Script check FAILED during Appid verification of …MSI and Script
8035ManagedInstaller Script check SUCCEEDED during Appid verification of …MSI and Script
8036CLSID was prevented from running due to Config CI policy.MSI and Script
8037FilePath passed Config CI policy and was allowed to run.MSI and Script
8038Publisher info.MSI and Script
8039Package family name Version version GUID was allowed to install or update but …MSI and Script
8040Package family name Version version GUID was prevented from installing or …MSI and Script
8041A Subject was allowed to ExecutionDecision by system execution policy.MSI and Script
8042A Subject was not allowed to be executed by system execution policy.MSI and Script
8043Process RegisterUninstallStringEventData.ProcessName attempted to register …EXE and DLL
8044Checking cmdline UninstallStringLength against registered UninstallStrings …EXE and DLL
8045Smart App Control Block DetailsMSI and Script
8045Operational
9000The application setting with ID 'AppID' and name 'SettingName' was queried.Verbose
9001The application setting with ID 'AppID' and name 'SettingName' was queried, and …Verbose

Event ID 8000 — AppID policy conversion failed.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Collection Priority
Recommended (ASD, others)

Description

AppID policy conversion failed. Status Status.

Message #

AppID policy conversion failed. Status %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 8001 — The AppLocker policy was applied successfully to this computer.

#
Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Level
Informational
Collection Priority
Recommended (ASD, others)

Description

The AppLocker policy was applied successfully to this computer.

Message #

The AppLocker policy was applied successfully to this computer.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AppLocker",
    "guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
    "event_source_name": "",
    "event_id": 8001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T23:50:01.740733+00:00",
    "event_record_id": 39,
    "correlation": {},
    "execution": {
      "process_id": 4372,
      "thread_id": 9624
    },
    "channel": "Microsoft-Windows-AppLocker/EXE and DLL",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8002 — FilePathBuffer was allowed to run.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Collection Priority
Recommended (NSA, others)

Description

FilePathBuffer was allowed to run.

Message #

%11 was allowed to run.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
FilePathLength UInt16
FilePathBuffer UnicodeString
FileHashLength UInt16
FileHash Binary
FqbnLength UInt16
Fqbn UnicodeString
TargetLogonId HexInt64
FullFilePathLength UInt16
FullFilePathBuffer UnicodeString

References #

Event ID 8003 — RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

#
Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Level
Warning
Collection Priority
Recommended (Palantir, others)

Description

RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Message #

%11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Fields #

NameDescription
RuleAndFileData.PolicyNameLength UInt16
RuleAndFileData.PolicyName
RuleAndFileData.RuleId GUID
RuleAndFileData.RuleNameLength UInt16
RuleAndFileData.RuleName
RuleAndFileData.RuleSddlLength UInt16
RuleAndFileData.RuleSddl
RuleAndFileData.TargetUser SID
RuleAndFileData.TargetProcessId UInt32
RuleAndFileData.FilePathLength UInt16
RuleAndFileData.FilePath
RuleAndFileData.FileHashLength UInt16
RuleAndFileData.FileHash Binary
RuleAndFileData.FqbnLength UInt16
RuleAndFileData.Fqbn UnicodeString
RuleAndFileData.TargetLogonId HexInt64
RuleAndFileData.FullFilePathLength UInt16
RuleAndFileData.FullFilePath
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
FilePathLength UInt16
FilePathBuffer UnicodeString
FileHashLength UInt16
FileHash Binary
FqbnLength UInt16
Fqbn UnicodeString
TargetLogonId HexInt64
FullFilePathLength UInt16
FullFilePathBuffer UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AppLocker",
    "guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
    "event_source_name": "",
    "event_id": 8003,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-02-17T22:20:35.068824+00:00",
    "event_record_id": 1172833,
    "correlation": {},
    "execution": {
      "process_id": 4668,
      "thread_id": 13560
    },
    "channel": "Microsoft-Windows-AppLocker/EXE and DLL",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "RuleAndFileData": {
      "PolicyNameLength": 3,
      "PolicyName": "DLL",
      "RuleId": "00000000-0000-0000-0000-000000000000",
      "RuleNameLength": 1,
      "RuleName": "-",
      "RuleSddlLength": 1,
      "RuleSddl": "-",
      "TargetUser": "S-1-5-18",
      "TargetProcessId": 4668,
      "FilePathLength": 38,
      "FilePath": "%SYSTEM32%\\ONDEMANDCONNROUTEHELPER.DLL",
      "FileHashLength": 0,
      "FileHash": null,
      "FqbnLength": 1,
      "Fqbn": "-",
      "TargetLogonId": "0x3e7",
      "FullFilePathLength": 47,
      "FullFilePath": "C:\\Windows\\system32\\OnDemandConnRouteHelper.dll"
    }
  },
  "message": ""
}

References #

Event ID 8004 — FilePathBuffer was prevented from running.

#
Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Collection Priority
Recommended (Palantir, others)

Description

FilePathBuffer was prevented from running.

Message #

%11 was prevented from running.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
FilePathLength UInt16
FilePathBuffer UnicodeString
FileHashLength UInt16
FileHash Binary
FqbnLength UInt16
Fqbn UnicodeString
TargetLogonId HexInt64
FullFilePathLength UInt16
FullFilePathBuffer UnicodeString

Detection Patterns #

References #

Event ID 8005 — FilePathBuffer was allowed to run.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (NSA, others)

Description

FilePathBuffer was allowed to run.

Message #

%11 was allowed to run.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
FilePathLength UInt16
FilePathBuffer UnicodeString
FileHashLength UInt16
FileHash Binary
FqbnLength UInt16
Fqbn UnicodeString
TargetLogonId HexInt64
FullFilePathLength UInt16
FullFilePathBuffer UnicodeString

References #

Event ID 8006 — FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (NSA, others)

Description

FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Message #

%11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
FilePathLength UInt16
FilePathBuffer UnicodeString
FileHashLength UInt16
FileHash Binary
FqbnLength UInt16
Fqbn UnicodeString
TargetLogonId HexInt64
FullFilePathLength UInt16
FullFilePathBuffer UnicodeString

References #

Event ID 8007 — FilePathBuffer was prevented from running.

#
Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (NSA, others)

Description

FilePathBuffer was prevented from running.

Message #

%11 was prevented from running.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
FilePathLength UInt16
FilePathBuffer UnicodeString
FileHashLength UInt16
FileHash Binary
FqbnLength UInt16
Fqbn UnicodeString
TargetLogonId HexInt64
FullFilePathLength UInt16
FullFilePathBuffer UnicodeString

Detection Patterns #

References #

Event ID 8008 — FilePathBuffer: AppLocker component not available on this SKU.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Collection Priority
Recommended (ASD, others)

Description

FilePathBuffer: AppLocker component not available on this SKU.

Message #

%2: AppLocker component not available on this SKU.

Fields #

NameDescription
FilePathLength UInt16
FilePathBuffer UnicodeString

Event ID 8009 — FilePathBuffer: AppLocker component not available on this SKU.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (Olaf Hartong)

Description

FilePathBuffer: AppLocker component not available on this SKU.

Message #

%2: AppLocker component not available on this SKU.

Fields #

NameDescription
FilePathLength UInt16
FilePathBuffer UnicodeString

Event ID 8010 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyConversion
Opcode
Start

Event ID 8011 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyConversion
Opcode
Stop

Event ID 8012 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyConversion
Opcode
Stop

Event ID 8013 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyRuleSort
Opcode
Start

Event ID 8014 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyRuleSort
Opcode
Stop

Event ID 8015 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyHitCountJoin
Opcode
Start

Event ID 8016 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyHitCountJoin
Opcode
Stop

Event ID 8017 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyLoad
Opcode
Start

Event ID 8018 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyLoad
Opcode
Stop

Event ID 8019 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Collection Priority
Recommended (Olaf Hartong)
Task
SrpPolicyLoad
Opcode
Stop

Event ID 8020 — PackageBuffer was allowed to run.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Execution
Collection Priority
Recommended (NSA, others)

Description

PackageBuffer was allowed to run.

Message #

%11 was allowed to run.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
PackageLength UInt16
PackageBuffer UnicodeString
FqbnLength UInt16
Fqbn UnicodeString

Event ID 8021 — PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Execution
Collection Priority
Recommended (Olaf Hartong)

Description

PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Message #

%11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
PackageLength UInt16
PackageBuffer UnicodeString
FqbnLength UInt16
Fqbn UnicodeString

Event ID 8022 — PackageBuffer was prevented from running.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Execution
Collection Priority
Recommended (ASD, others)

Description

PackageBuffer was prevented from running.

Message #

%11 was prevented from running.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
PackageLength UInt16
PackageBuffer UnicodeString
FqbnLength UInt16
Fqbn UnicodeString

Detection Patterns #

Event ID 8023 — PackageBuffer was allowed to be installed.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Deployment
Collection Priority
Recommended (NSA, others)

Description

PackageBuffer was allowed to be installed.

Message #

%11 was allowed to be installed.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
PackageLength UInt16
PackageBuffer UnicodeString
FqbnLength UInt16
Fqbn UnicodeString

Event ID 8024 — PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Deployment
Collection Priority
Recommended (Olaf Hartong)

Description

PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Message #

%11 was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
PackageLength UInt16
PackageBuffer UnicodeString
FqbnLength UInt16
Fqbn UnicodeString

Event ID 8025 — PackageBuffer was prevented from running.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Deployment
Collection Priority
Recommended (ASD, others)

Description

PackageBuffer was prevented from running.

Message #

%11 was prevented from running.

Fields #

NameDescription
PolicyNameLength UInt16
PolicyNameBuffer UnicodeString
RuleId GUID
RuleNameLength UInt16
RuleNameBuffer UnicodeString
RuleSddlLength UInt16
RuleSddlBuffer UnicodeString
TargetUser SID
TargetProcessId UInt32
PackageLength UInt16
PackageBuffer UnicodeString
FqbnLength UInt16
Fqbn UnicodeString

Detection Patterns #

Event ID 8026 — No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Deployment
Collection Priority
Recommended (Olaf Hartong)

Description

No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.

Message #

No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.

Event ID 8027 — No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.

Provider
Microsoft-Windows-AppLocker
Channel
Packaged app-Execution
Collection Priority
Recommended (ASD, others)

Description

No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.

Message #

No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.

Event ID 8028 — FilePath was allowed to run but would have been prevented if the Config CI policy were enforced.

#
Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Level
Warning

Description

FilePath was allowed to run but would have been prevented if the Config CI policy were enforced.

Message #

%2 was allowed to run but would have been prevented if the Config CI policy were enforced.

Fields #

NameDescription
FilePathLength UInt16
FilePath UnicodeString
Sha1Hash Binary
Sha256Hash Binary
Result Int32
USN Int64
Sha1CatalogHash Binary
Sha256CatalogHash Binary
UserWriteable Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AppLocker",
    "guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
    "event_source_name": "",
    "event_id": 8028,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T00:54:55.214802+00:00",
    "event_record_id": 241,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-6B7D-E5E43710DA01"
    },
    "execution": {
      "process_id": 12792,
      "thread_id": 6736
    },
    "channel": "Microsoft-Windows-AppLocker/MSI and Script",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "FilePathLength": 70,
    "FilePath": "C:\\Windows\\Installer\\{6F11CAC3-D33D-4360-B139-73F3276A2B9A}\\loc.en.mst",
    "Sha1Hash": "C9FD8657FD8262EF19369B5FB6CAA7CB7632FC87",
    "Sha256Hash": "3881BD701A2B9DE71742065AADC110FBFFD17F127785FDA4E17570A77FC3FA84",
    "Result": -790036478,
    "USN": 309169000,
    "Sha1CatalogHash": "C9FD8657FD8262EF19369B5FB6CAA7CB7632FC87",
    "Sha256CatalogHash": "9A71D576BC994B8C6DCFA683B38313596DCE7774784D46EFC5FE5D97724043BC",
    "UserWriteable": false
  },
  "message": ""
}

References #

Event ID 8029 — FilePath was prevented from running due to Config CI policy.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (ASD)

Description

FilePath was prevented from running due to Config CI policy.

Message #

%2 was prevented from running due to Config CI policy.

Fields #

NameDescription
FilePathLength UInt16
FilePath UnicodeString
Sha1Hash Binary
Sha256Hash Binary
Result Int32
USN Int64
Sha1CatalogHash Binary
Sha256CatalogHash Binary
UserWriteable Boolean
DetachedSignatureFilePathLength UInt16
DetachedSignatureFilePath UnicodeString
OriginalFileNameLength UInt16
OriginalFilename UnicodeString
InternalNameLength UInt16
InternalName UnicodeString
FileDescriptionLength UInt16
FileDescription UnicodeString
ProductNameLength UInt16
ProductName UnicodeString
FileVersionLength UInt16
FileVersion UnicodeString
PolicyNameLength UInt16
PolicyName UnicodeString
PolicyIDLength UInt16
PolicyID UnicodeString
PolicyGUID GUID

References #

Event ID 8030 — ManagedInstaller check SUCCEEDED during Appid verification of ImageNameLength.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL

Description

ManagedInstaller check SUCCEEDED during Appid verification of.

Message #

ManagedInstaller check SUCCEEDED during Appid verification of
%2.
Status: %5

Fields #

NameDescription
StatusNTSTATUS reference
ImageNameLength UInt16
ImageName UnicodeString
ParentProcessLength UInt16
ParentProcess AnsiString
StatusCode HexInt32
AppLockerReason UInt32
Bucket UInt32
USN UInt64
NtfsFileIdSize UInt16
NtfsFileId Binary
OriginDataPresent Boolean
SessionId GUID
SubSessionId GUID
Origin UInt32
Type UInt32
Generation UInt32
SmartScreen UInt32
RevocationID UInt32
DataLength UInt16
Data UnicodeString

Event ID 8031 — SmartlockerFilter detected file FileName being written by process CurrentProcess.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL

Description

SmartlockerFilter detected file FileName being written by process CurrentProcess.

Message #

SmartlockerFilter detected file %2 being written by process %4.

Fields #

NameDescription
FileNameLength UInt16
FileName UnicodeString
CurrentProcessLength UInt16
CurrentProcess AnsiString
ParentProcessLength UInt16
ParentProcess AnsiString
USN UInt64
NtfsFileIdSize UInt16
NtfsFileId Binary
OriginDataPresent Boolean
SessionId GUID
Origin UInt32
Type UInt32
Generation UInt32
SmartScreen UInt32
DataLength UInt16
Data UnicodeString

Event ID 8032 — ManagedInstaller check FAILED during Appid verification of ImageNameLength.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Collection Priority
Recommended (ASD)

Description

ManagedInstaller check FAILED during Appid verification of.

Message #

ManagedInstaller check FAILED during Appid verification of
%2.
Status: %5

Fields #

NameDescription
StatusNTSTATUS reference
ImageNameLength UInt16
ImageName UnicodeString
ParentProcessLength UInt16
ParentProcess AnsiString
StatusCode HexInt32
AppLockerReason UInt32
Bucket UInt32
USN UInt64
NtfsFileIdSize UInt16
NtfsFileId Binary
OriginDataPresent Boolean
SessionId GUID
SubSessionId GUID
Origin UInt32
Type UInt32
Generation UInt32
SmartScreen UInt32
RevocationID UInt32
DataLength UInt16
Data UnicodeString

Event ID 8033 — ManagedInstaller check FAILED during Appid verification of ImageNameLength.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL

Description

ManagedInstaller check FAILED during Appid verification of.

Message #

ManagedInstaller check FAILED during Appid verification of
%2.
Status: %5
Allowed to run due to Audit Applocker Policy

Fields #

NameDescription
StatusNTSTATUS reference
ImageNameLength UInt16
ImageName UnicodeString
ParentProcessLength UInt16
ParentProcess AnsiString
StatusCode HexInt32
AppLockerReason UInt32
Bucket UInt32
USN UInt64
NtfsFileIdSize UInt16
NtfsFileId Binary
OriginDataPresent Boolean
SessionId GUID
SubSessionId GUID
Origin UInt32
Type UInt32
Generation UInt32
SmartScreen UInt32
RevocationID UInt32
DataLength UInt16
Data UnicodeString

Event ID 8034 — ManagedInstaller Script check FAILED during Appid verification of ImageNameLength.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script

Description

ManagedInstaller Script check FAILED during Appid verification of.

Message #

ManagedInstaller Script check FAILED during Appid verification of
%2.
Status: %3

Fields #

NameDescription
StatusNTSTATUS reference
ImageNameLength UInt16
ImageName UnicodeString
StatusCode HexInt32
Bucket UInt32
OriginDataPresent Boolean
SessionId GUID
SubSessionId GUID
Origin UInt32
Type UInt32
Generation UInt32
SmartScreen UInt32
RevocationID UInt32
DataLength UInt16
Data UnicodeString

Event ID 8035 — ManagedInstaller Script check SUCCEEDED during Appid verification of ImageNameLength.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (ASD)

Description

ManagedInstaller Script check SUCCEEDED during Appid verification of.

Message #

ManagedInstaller Script check SUCCEEDED during Appid verification of
%2.
Status: %3

Fields #

NameDescription
StatusNTSTATUS reference
ImageNameLength UInt16
ImageName UnicodeString
StatusCode HexInt32
Bucket UInt32
OriginDataPresent Boolean
SessionId GUID
SubSessionId GUID
Origin UInt32
Type UInt32
Generation UInt32
SmartScreen UInt32
RevocationID UInt32
DataLength UInt16
Data UnicodeString

Event ID 8036 — CLSID was prevented from running due to Config CI policy.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (ASD)

Description

CLSID was prevented from running due to Config CI policy.

Message #

%2 was prevented from running due to Config CI policy.

Fields #

NameDescription
IsApproved Boolean
CLSID GUID

References #

Event ID 8037 — FilePath passed Config CI policy and was allowed to run.

#
Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Level
Informational

Description

FilePath passed Config CI policy and was allowed to run.

Message #

%2 passed Config CI policy and was allowed to run.

Fields #

NameDescription
FilePathLength UInt16
FilePath UnicodeString
Sha1Hash Binary
Sha256Hash Binary
Result Int32
USN Int64
Sha1CatalogHash Binary
Sha256CatalogHash Binary
UserWriteable Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AppLocker",
    "guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
    "event_source_name": "",
    "event_id": 8037,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T23:23:27.417018+00:00",
    "event_record_id": 212,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-B137-E1E43710DA01"
    },
    "execution": {
      "process_id": 4436,
      "thread_id": 4748
    },
    "channel": "Microsoft-Windows-AppLocker/MSI and Script",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "FilePathLength": 52,
    "FilePath": "C:\\Users\\User\\AppData\\Local\\Temp\\5727A9~1\\target.msi",
    "Sha1Hash": "BZ5vuVS8kFhj0G/vkELAqCSVqZQ=",
    "Sha256Hash": "V6OaWrftehYv3pf3Ok8wTra6kixgNW/+/Gv+5qiK/k4=",
    "Result": "",
    "USN": "p�t\u0010",
    "Sha1CatalogHash": "BZ5vuVS8kFhj0G/vkELAqCSVqZQ=",
    "Sha256CatalogHash": "vuwjuOrQZfho6c2gISZZmGl+eXBkI0qHyIi+luLHAGA=",
    "UserWriteable": true
  },
  "message": ""
}

References #

Event ID 8038 — Publisher info.

#
Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Level
Informational

Description

Publisher info.

Message #

Publisher info:
Subject: %4
Issuer: %6
Signature index %2 (%1 total)

Fields #

NameDescription
TotalSignatureCount UInt32
Signature UInt32
PublisherNameLength UInt16
PublisherName UnicodeString
IssuerNameLength UInt16
IssuerName UnicodeString
PublisherTBSHashSize UInt32
PublisherTBSHash Binary
IssuerTBSHashSize UInt32
IssuerTBSHash Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AppLocker",
    "guid": "{cbda4dbf-8d5d-4f69-9578-be14aa540d22}",
    "event_source_name": "",
    "event_id": 8038,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T00:54:55.214842+00:00",
    "event_record_id": 242,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-6B7D-E5E43710DA01"
    },
    "execution": {
      "process_id": 12792,
      "thread_id": 6736
    },
    "channel": "Microsoft-Windows-AppLocker/MSI and Script",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8039 — Package family name Version version GUID was allowed to install or update but would have been prevented if the Config CI policy.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script

Description

Package family name Version version GUID was allowed to install or update but would have been prevented if the Config CI policy (Name:PackageFamilyName ID:PolicyNameLength Version:PolicyName GUID:PolicyIDLength) were enforced. Status PolicyID.

Message #

Package family name %2 version %3 was allowed to install or update but would have been prevented if the Config CI policy (Name:%5 ID:%7 Version:%8 GUID:%9) were enforced. Status %10

Fields #

NameDescription
ID
Version
GUID
PackageFamilyNameLength UInt16
PackageFamilyName UnicodeString
PackageVersion UInt64
PolicyNameLength UInt16
PolicyName UnicodeString
PolicyIDLength UInt16
PolicyID UnicodeString
PolicyVersion UInt64
PolicyGuid GUID
Status HexInt32NTSTATUS reference

References #

Event ID 8040 — Package family name Version version GUID was prevented from installing or updating due to Config CI policy (Name:PackageFamilyName ID:PolicyNameLength Version:PolicyName GUID:PolicyIDLength).

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Collection Priority
Recommended (ASD)

Description

Package family name Version version GUID was prevented from installing or updating due to Config CI policy (Name:PackageFamilyName ID:PolicyNameLength Version:PolicyName GUID:PolicyIDLength). Status PolicyID.

Message #

Package family name %2 version %3 was prevented from installing or updating due to Config CI policy (Name:%5 ID:%7 Version:%8 GUID:%9). Status %10

Fields #

NameDescription
ID
Version
GUID
PackageFamilyNameLength UInt16
PackageFamilyName UnicodeString
PackageVersion UInt64
PolicyNameLength UInt16
PolicyName UnicodeString
PolicyIDLength UInt16
PolicyID UnicodeString
PolicyVersion UInt64
PolicyGuid GUID
Status HexInt32NTSTATUS reference

References #

Event ID 8041 — A Subject was allowed to ExecutionDecision by system execution policy.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script

Description

A Subject was allowed to ExecutionDecision by system execution policy. The application provided this information: 'AuditInfo'.

Message #

A %6 was allowed to %1 by system execution policy. The application provided this information: '%3'

Fields #

NameDescription
ExecutionDecision UInt32
AuditInfoLength UInt32
AuditInfo UnicodeString
ExecutionOptionFlags UInt32
Host GUID
Subject UInt32

Event ID 8042 — A Subject was not allowed to be executed by system execution policy.

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script

Description

A Subject was not allowed to be executed by system execution policy. The application provided this information: 'AuditInfo'.

Message #

A %6 was not allowed to be executed by system execution policy. The application provided this information: '%3'

Fields #

NameDescription
ExecutionDecision UInt32
AuditInfoLength UInt32
AuditInfo UnicodeString
ExecutionOptionFlags UInt32
Host GUID
Subject UInt32

Event ID 8043 — Process RegisterUninstallStringEventData.ProcessName attempted to register UninstallString RegisterUninstallStringEventData.UninstallString, Status: RegisterUninstallStringEventData.Status.

#
Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL
Level
Informational

Description

Process RegisterUninstallStringEventData.ProcessName attempted to register UninstallString RegisterUninstallStringEventData.UninstallString, Status: RegisterUninstallStringEventData.Status.

Message #

Process %6 attempted to register UninstallString %2, Status: %9.

Fields #

NameDescription
RegisterUninstallStringEventData.UninstallStringLength
RegisterUninstallStringEventData.UninstallString
RegisterUninstallStringEventData.UninstallerPathLength
RegisterUninstallStringEventData.UninstallerPath
RegisterUninstallStringEventData.ProcessNameLength
RegisterUninstallStringEventData.ProcessName
RegisterUninstallStringEventData.SessionId
RegisterUninstallStringEventData.SubSessionId
RegisterUninstallStringEventData.Status2, Status.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-AppLocker",
    "guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
    "event_source_name": "",
    "event_id": 8043,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T01:02:05.721093+00:00",
    "event_record_id": 43,
    "correlation": {},
    "execution": {
      "process_id": 12912,
      "thread_id": 13892
    },
    "channel": "Microsoft-Windows-AppLocker/EXE and DLL",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "user_data": {
    "RegisterUninstallStringEventData": {
      "UninstallStringLength": 43,
      "UninstallString": "\"C:\\Program Files\\TeamViewer\\uninstall.exe\"",
      "UninstallerPathLength": 53,
      "UninstallerPath": "\\DosDevices\\C:\\Program Files\\TeamViewer\\uninstall.exe",
      "ProcessNameLength": 78,
      "ProcessName": "\\Device\\HarddiskVolume4\\Users\\User\\AppData\\Local\\Temp\\CDD35C~1\\TeamViewer_.exe",
      "SessionId": "F205B252-1454-4144-BD5A-E00D8E398514",
      "SubSessionId": "0A236C0E-D7AD-508F-13CB-E8248F7D7476",
      "Status": 0
    }
  },
  "message": ""
}

References #

Event ID 8044 — Checking cmdline UninstallStringLength against registered UninstallStrings CmdlineLength, MatchFound: Cmdline, Status:MatchFound.

Provider
Microsoft-Windows-AppLocker
Channel
EXE and DLL

Description

Checking cmdline UninstallStringLength against registered UninstallStrings CmdlineLength, MatchFound: Cmdline, Status:MatchFound.

Message #

Checking cmdline %2 against registered UninstallStrings %4, MatchFound: %5, Status:%6.

Fields #

NameDescription
Status HexInt32NTSTATUS reference
UninstallStringLength UInt16
UninstallString UnicodeString
CmdlineLength UInt16
Cmdline UnicodeString
MatchFound Boolean

Event ID 8045 — Smart App Control Block Details

Provider
Microsoft-Windows-AppLocker
Channel
MSI and Script
Task
SmartAppControlBlockDetailsTask
Opcode
SmartAppControlBlockDetailsOp

Description

Smart App Control Block Details.

Message #

Smart App Control Block Details

Fields #

NameDescription
FilePathLength UInt16
FilePathBuffer UnicodeString
FileSha256Hash Binary
DefenderScanResultDetails UInt32
DefenderClientStatusCode Int32
DefenderCloudHTTPCode HexInt32
DefenderEngineReportGUID GUID
DefenderFlags Int64
DefenderCalled UInt32
DefenderCallAttempted UInt32
DefenderCloudCallRequested UInt32
DefenderMadeCloudCall UInt32
ExternalAuthorizationFlags UInt32

Event ID 8045 —

Provider
Microsoft-Windows-AppLocker
Channel
Operational
Task
SmartAppControlBlockDetailsTask
Opcode
SmartAppControlBlockDetailsOp

Description

Smart App Control Block Details.

Fields #

NameDescription
FilePathLength UInt16
FilePathBuffer UnicodeString
FileSha256Hash Binary
DefenderScanResultDetails UInt32
DefenderClientStatusCode Int32
DefenderCloudHTTPCode HexInt32
DefenderEngineReportGUID GUID
DefenderFlags Int64
DefenderCalled UInt32
DefenderCallAttempted UInt32
DefenderCloudCallRequested UInt32
DefenderMadeCloudCall UInt32
ExternalAuthorizationFlags UInt32

Event ID 9000 — The application setting with ID 'AppID' and name 'SettingName' was queried.

Provider
Microsoft-Windows-AppLocker
Channel
Verbose

Description

The application setting with ID 'AppID' and name 'SettingName' was queried. For more information, see the details tab.

Message #

The application setting with ID '%1' and name '%2' was queried. For more information, see the details tab.

Fields #

NameDescription
AppID UnicodeString
SettingName UnicodeString
SettingType UInt32
ValueCount UInt32
Value UnicodeString

Event ID 9001 — The application setting with ID 'AppID' and name 'SettingName' was queried, and would have a different a value if all policies were enforcing.

Provider
Microsoft-Windows-AppLocker
Channel
Verbose

Description

The application setting with ID 'AppID' and name 'SettingName' was queried, and would have a different a value if all policies were enforcing. For more information, see the details tab.

Message #

The application setting with ID '%1' and name '%2' was queried, and would have a different a value if all policies were enforcing. For more information, see the details tab.

Fields #

NameDescription
AppID UnicodeString
SettingName UnicodeString
SettingType UInt32
ValueCount UInt32
Value UnicodeString
AuditValueCount UInt32
AuditValue UnicodeString