Microsoft-Windows-AppLocker
49 events across 6 channels
Event ID 8000 — AppID policy conversion failed.
Description
AppID policy conversion failed. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 8001 — The AppLocker policy was applied successfully to this computer.
#Description
The AppLocker policy was applied successfully to this computer.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-AppLocker",
"guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
"event_source_name": "",
"event_id": 8001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T23:50:01.740733+00:00",
"event_record_id": 39,
"correlation": {},
"execution": {
"process_id": 4372,
"thread_id": 9624
},
"channel": "Microsoft-Windows-AppLocker/EXE and DLL",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8002 — FilePathBuffer was allowed to run.
Description
FilePathBuffer was allowed to run.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileHashLength UInt16 | — |
FileHash Binary | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
TargetLogonId HexInt64 | — |
FullFilePathLength UInt16 | — |
FullFilePathBuffer UnicodeString | — |
References #
Event ID 8003 — RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
#Description
RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Message #
Fields #
| Name | Description |
|---|---|
RuleAndFileData.PolicyNameLength UInt16 | — |
RuleAndFileData.PolicyName | — |
RuleAndFileData.RuleId GUID | — |
RuleAndFileData.RuleNameLength UInt16 | — |
RuleAndFileData.RuleName | — |
RuleAndFileData.RuleSddlLength UInt16 | — |
RuleAndFileData.RuleSddl | — |
RuleAndFileData.TargetUser SID | — |
RuleAndFileData.TargetProcessId UInt32 | — |
RuleAndFileData.FilePathLength UInt16 | — |
RuleAndFileData.FilePath | — |
RuleAndFileData.FileHashLength UInt16 | — |
RuleAndFileData.FileHash Binary | — |
RuleAndFileData.FqbnLength UInt16 | — |
RuleAndFileData.Fqbn UnicodeString | — |
RuleAndFileData.TargetLogonId HexInt64 | — |
RuleAndFileData.FullFilePathLength UInt16 | — |
RuleAndFileData.FullFilePath | — |
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileHashLength UInt16 | — |
FileHash Binary | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
TargetLogonId HexInt64 | — |
FullFilePathLength UInt16 | — |
FullFilePathBuffer UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-AppLocker",
"guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
"event_source_name": "",
"event_id": 8003,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-02-17T22:20:35.068824+00:00",
"event_record_id": 1172833,
"correlation": {},
"execution": {
"process_id": 4668,
"thread_id": 13560
},
"channel": "Microsoft-Windows-AppLocker/EXE and DLL",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"RuleAndFileData": {
"PolicyNameLength": 3,
"PolicyName": "DLL",
"RuleId": "00000000-0000-0000-0000-000000000000",
"RuleNameLength": 1,
"RuleName": "-",
"RuleSddlLength": 1,
"RuleSddl": "-",
"TargetUser": "S-1-5-18",
"TargetProcessId": 4668,
"FilePathLength": 38,
"FilePath": "%SYSTEM32%\\ONDEMANDCONNROUTEHELPER.DLL",
"FileHashLength": 0,
"FileHash": null,
"FqbnLength": 1,
"Fqbn": "-",
"TargetLogonId": "0x3e7",
"FullFilePathLength": 47,
"FullFilePath": "C:\\Windows\\system32\\OnDemandConnRouteHelper.dll"
}
},
"message": ""
}
References #
Event ID 8004 — FilePathBuffer was prevented from running.
#Description
FilePathBuffer was prevented from running.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileHashLength UInt16 | — |
FileHash Binary | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
TargetLogonId HexInt64 | — |
FullFilePathLength UInt16 | — |
FullFilePathBuffer UnicodeString | — |
Detection Patterns #
References #
Event ID 8005 — FilePathBuffer was allowed to run.
Description
FilePathBuffer was allowed to run.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileHashLength UInt16 | — |
FileHash Binary | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
TargetLogonId HexInt64 | — |
FullFilePathLength UInt16 | — |
FullFilePathBuffer UnicodeString | — |
References #
Event ID 8006 — FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Description
FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileHashLength UInt16 | — |
FileHash Binary | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
TargetLogonId HexInt64 | — |
FullFilePathLength UInt16 | — |
FullFilePathBuffer UnicodeString | — |
References #
Event ID 8007 — FilePathBuffer was prevented from running.
#Description
FilePathBuffer was prevented from running.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileHashLength UInt16 | — |
FileHash Binary | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
TargetLogonId HexInt64 | — |
FullFilePathLength UInt16 | — |
FullFilePathBuffer UnicodeString | — |
Detection Patterns #
References #
Event ID 8008 — FilePathBuffer: AppLocker component not available on this SKU.
Event ID 8009 — FilePathBuffer: AppLocker component not available on this SKU.
Event ID 8010 —
Event ID 8011 —
Event ID 8012 —
Event ID 8013 —
Event ID 8014 —
Event ID 8015 —
Event ID 8016 —
Event ID 8017 —
Event ID 8018 —
Event ID 8019 —
Event ID 8020 — PackageBuffer was allowed to run.
Description
PackageBuffer was allowed to run.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
PackageLength UInt16 | — |
PackageBuffer UnicodeString | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
Event ID 8021 — PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Description
PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
PackageLength UInt16 | — |
PackageBuffer UnicodeString | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
Event ID 8022 — PackageBuffer was prevented from running.
Description
PackageBuffer was prevented from running.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
PackageLength UInt16 | — |
PackageBuffer UnicodeString | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
Detection Patterns #
Event ID 8023 — PackageBuffer was allowed to be installed.
Description
PackageBuffer was allowed to be installed.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
PackageLength UInt16 | — |
PackageBuffer UnicodeString | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
Event ID 8024 — PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Description
PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
PackageLength UInt16 | — |
PackageBuffer UnicodeString | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
Event ID 8025 — PackageBuffer was prevented from running.
Description
PackageBuffer was prevented from running.
Message #
Fields #
| Name | Description |
|---|---|
PolicyNameLength UInt16 | — |
PolicyNameBuffer UnicodeString | — |
RuleId GUID | — |
RuleNameLength UInt16 | — |
RuleNameBuffer UnicodeString | — |
RuleSddlLength UInt16 | — |
RuleSddlBuffer UnicodeString | — |
TargetUser SID | — |
TargetProcessId UInt32 | — |
PackageLength UInt16 | — |
PackageBuffer UnicodeString | — |
FqbnLength UInt16 | — |
Fqbn UnicodeString | — |
Detection Patterns #
Event ID 8026 — No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.
Description
No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.
Message #
Event ID 8027 — No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.
Description
No packaged apps can be executed while Exe rules are being enforced and no Packaged app rules have been configured.
Message #
Event ID 8028 — FilePath was allowed to run but would have been prevented if the Config CI policy were enforced.
#Description
FilePath was allowed to run but would have been prevented if the Config CI policy were enforced.
Message #
Fields #
| Name | Description |
|---|---|
FilePathLength UInt16 | — |
FilePath UnicodeString | — |
Sha1Hash Binary | — |
Sha256Hash Binary | — |
Result Int32 | — |
USN Int64 | — |
Sha1CatalogHash Binary | — |
Sha256CatalogHash Binary | — |
UserWriteable Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-AppLocker",
"guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
"event_source_name": "",
"event_id": 8028,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T00:54:55.214802+00:00",
"event_record_id": 241,
"correlation": {
"ActivityID": "E4DB489E-1037-0001-6B7D-E5E43710DA01"
},
"execution": {
"process_id": 12792,
"thread_id": 6736
},
"channel": "Microsoft-Windows-AppLocker/MSI and Script",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"FilePathLength": 70,
"FilePath": "C:\\Windows\\Installer\\{6F11CAC3-D33D-4360-B139-73F3276A2B9A}\\loc.en.mst",
"Sha1Hash": "C9FD8657FD8262EF19369B5FB6CAA7CB7632FC87",
"Sha256Hash": "3881BD701A2B9DE71742065AADC110FBFFD17F127785FDA4E17570A77FC3FA84",
"Result": -790036478,
"USN": 309169000,
"Sha1CatalogHash": "C9FD8657FD8262EF19369B5FB6CAA7CB7632FC87",
"Sha256CatalogHash": "9A71D576BC994B8C6DCFA683B38313596DCE7774784D46EFC5FE5D97724043BC",
"UserWriteable": false
},
"message": ""
}
References #
Event ID 8029 — FilePath was prevented from running due to Config CI policy.
Description
FilePath was prevented from running due to Config CI policy.
Message #
Fields #
| Name | Description |
|---|---|
FilePathLength UInt16 | — |
FilePath UnicodeString | — |
Sha1Hash Binary | — |
Sha256Hash Binary | — |
Result Int32 | — |
USN Int64 | — |
Sha1CatalogHash Binary | — |
Sha256CatalogHash Binary | — |
UserWriteable Boolean | — |
DetachedSignatureFilePathLength UInt16 | — |
DetachedSignatureFilePath UnicodeString | — |
OriginalFileNameLength UInt16 | — |
OriginalFilename UnicodeString | — |
InternalNameLength UInt16 | — |
InternalName UnicodeString | — |
FileDescriptionLength UInt16 | — |
FileDescription UnicodeString | — |
ProductNameLength UInt16 | — |
ProductName UnicodeString | — |
FileVersionLength UInt16 | — |
FileVersion UnicodeString | — |
PolicyNameLength UInt16 | — |
PolicyName UnicodeString | — |
PolicyIDLength UInt16 | — |
PolicyID UnicodeString | — |
PolicyGUID GUID | — |
References #
Event ID 8030 — ManagedInstaller check SUCCEEDED during Appid verification of ImageNameLength.
Description
ManagedInstaller check SUCCEEDED during Appid verification of.
Message #
Fields #
| Name | Description |
|---|---|
Status | — NTSTATUS reference |
ImageNameLength UInt16 | — |
ImageName UnicodeString | — |
ParentProcessLength UInt16 | — |
ParentProcess AnsiString | — |
StatusCode HexInt32 | — |
AppLockerReason UInt32 | — |
Bucket UInt32 | — |
USN UInt64 | — |
NtfsFileIdSize UInt16 | — |
NtfsFileId Binary | — |
OriginDataPresent Boolean | — |
SessionId GUID | — |
SubSessionId GUID | — |
Origin UInt32 | — |
Type UInt32 | — |
Generation UInt32 | — |
SmartScreen UInt32 | — |
RevocationID UInt32 | — |
DataLength UInt16 | — |
Data UnicodeString | — |
Event ID 8031 — SmartlockerFilter detected file FileName being written by process CurrentProcess.
Description
SmartlockerFilter detected file FileName being written by process CurrentProcess.
Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CurrentProcessLength UInt16 | — |
CurrentProcess AnsiString | — |
ParentProcessLength UInt16 | — |
ParentProcess AnsiString | — |
USN UInt64 | — |
NtfsFileIdSize UInt16 | — |
NtfsFileId Binary | — |
OriginDataPresent Boolean | — |
SessionId GUID | — |
Origin UInt32 | — |
Type UInt32 | — |
Generation UInt32 | — |
SmartScreen UInt32 | — |
DataLength UInt16 | — |
Data UnicodeString | — |
Event ID 8032 — ManagedInstaller check FAILED during Appid verification of ImageNameLength.
Description
ManagedInstaller check FAILED during Appid verification of.
Message #
Fields #
| Name | Description |
|---|---|
Status | — NTSTATUS reference |
ImageNameLength UInt16 | — |
ImageName UnicodeString | — |
ParentProcessLength UInt16 | — |
ParentProcess AnsiString | — |
StatusCode HexInt32 | — |
AppLockerReason UInt32 | — |
Bucket UInt32 | — |
USN UInt64 | — |
NtfsFileIdSize UInt16 | — |
NtfsFileId Binary | — |
OriginDataPresent Boolean | — |
SessionId GUID | — |
SubSessionId GUID | — |
Origin UInt32 | — |
Type UInt32 | — |
Generation UInt32 | — |
SmartScreen UInt32 | — |
RevocationID UInt32 | — |
DataLength UInt16 | — |
Data UnicodeString | — |
Event ID 8033 — ManagedInstaller check FAILED during Appid verification of ImageNameLength.
Description
ManagedInstaller check FAILED during Appid verification of.
Message #
Fields #
| Name | Description |
|---|---|
Status | — NTSTATUS reference |
ImageNameLength UInt16 | — |
ImageName UnicodeString | — |
ParentProcessLength UInt16 | — |
ParentProcess AnsiString | — |
StatusCode HexInt32 | — |
AppLockerReason UInt32 | — |
Bucket UInt32 | — |
USN UInt64 | — |
NtfsFileIdSize UInt16 | — |
NtfsFileId Binary | — |
OriginDataPresent Boolean | — |
SessionId GUID | — |
SubSessionId GUID | — |
Origin UInt32 | — |
Type UInt32 | — |
Generation UInt32 | — |
SmartScreen UInt32 | — |
RevocationID UInt32 | — |
DataLength UInt16 | — |
Data UnicodeString | — |
Event ID 8034 — ManagedInstaller Script check FAILED during Appid verification of ImageNameLength.
Description
ManagedInstaller Script check FAILED during Appid verification of.
Message #
Fields #
| Name | Description |
|---|---|
Status | — NTSTATUS reference |
ImageNameLength UInt16 | — |
ImageName UnicodeString | — |
StatusCode HexInt32 | — |
Bucket UInt32 | — |
OriginDataPresent Boolean | — |
SessionId GUID | — |
SubSessionId GUID | — |
Origin UInt32 | — |
Type UInt32 | — |
Generation UInt32 | — |
SmartScreen UInt32 | — |
RevocationID UInt32 | — |
DataLength UInt16 | — |
Data UnicodeString | — |
Event ID 8035 — ManagedInstaller Script check SUCCEEDED during Appid verification of ImageNameLength.
Description
ManagedInstaller Script check SUCCEEDED during Appid verification of.
Message #
Fields #
| Name | Description |
|---|---|
Status | — NTSTATUS reference |
ImageNameLength UInt16 | — |
ImageName UnicodeString | — |
StatusCode HexInt32 | — |
Bucket UInt32 | — |
OriginDataPresent Boolean | — |
SessionId GUID | — |
SubSessionId GUID | — |
Origin UInt32 | — |
Type UInt32 | — |
Generation UInt32 | — |
SmartScreen UInt32 | — |
RevocationID UInt32 | — |
DataLength UInt16 | — |
Data UnicodeString | — |
Event ID 8036 — CLSID was prevented from running due to Config CI policy.
Event ID 8037 — FilePath passed Config CI policy and was allowed to run.
#Description
FilePath passed Config CI policy and was allowed to run.
Message #
Fields #
| Name | Description |
|---|---|
FilePathLength UInt16 | — |
FilePath UnicodeString | — |
Sha1Hash Binary | — |
Sha256Hash Binary | — |
Result Int32 | — |
USN Int64 | — |
Sha1CatalogHash Binary | — |
Sha256CatalogHash Binary | — |
UserWriteable Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-AppLocker",
"guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
"event_source_name": "",
"event_id": 8037,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-05T23:23:27.417018+00:00",
"event_record_id": 212,
"correlation": {
"ActivityID": "E4DB489E-1037-0000-B137-E1E43710DA01"
},
"execution": {
"process_id": 4436,
"thread_id": 4748
},
"channel": "Microsoft-Windows-AppLocker/MSI and Script",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {
"FilePathLength": 52,
"FilePath": "C:\\Users\\User\\AppData\\Local\\Temp\\5727A9~1\\target.msi",
"Sha1Hash": "BZ5vuVS8kFhj0G/vkELAqCSVqZQ=",
"Sha256Hash": "V6OaWrftehYv3pf3Ok8wTra6kixgNW/+/Gv+5qiK/k4=",
"Result": "",
"USN": "p�t\u0010",
"Sha1CatalogHash": "BZ5vuVS8kFhj0G/vkELAqCSVqZQ=",
"Sha256CatalogHash": "vuwjuOrQZfho6c2gISZZmGl+eXBkI0qHyIi+luLHAGA=",
"UserWriteable": true
},
"message": ""
}
References #
Event ID 8038 — Publisher info.
#Description
Publisher info.
Message #
Fields #
| Name | Description |
|---|---|
TotalSignatureCount UInt32 | — |
Signature UInt32 | — |
PublisherNameLength UInt16 | — |
PublisherName UnicodeString | — |
IssuerNameLength UInt16 | — |
IssuerName UnicodeString | — |
PublisherTBSHashSize UInt32 | — |
PublisherTBSHash Binary | — |
IssuerTBSHashSize UInt32 | — |
IssuerTBSHash Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-AppLocker",
"guid": "{cbda4dbf-8d5d-4f69-9578-be14aa540d22}",
"event_source_name": "",
"event_id": 8038,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T00:54:55.214842+00:00",
"event_record_id": 242,
"correlation": {
"ActivityID": "E4DB489E-1037-0001-6B7D-E5E43710DA01"
},
"execution": {
"process_id": 12792,
"thread_id": 6736
},
"channel": "Microsoft-Windows-AppLocker/MSI and Script",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
Event ID 8039 — Package family name Version version GUID was allowed to install or update but would have been prevented if the Config CI policy.
Description
Package family name Version version GUID was allowed to install or update but would have been prevented if the Config CI policy (Name:PackageFamilyName ID:PolicyNameLength Version:PolicyName GUID:PolicyIDLength) were enforced. Status PolicyID.
Message #
Fields #
| Name | Description |
|---|---|
ID | — |
Version | — |
GUID | — |
PackageFamilyNameLength UInt16 | — |
PackageFamilyName UnicodeString | — |
PackageVersion UInt64 | — |
PolicyNameLength UInt16 | — |
PolicyName UnicodeString | — |
PolicyIDLength UInt16 | — |
PolicyID UnicodeString | — |
PolicyVersion UInt64 | — |
PolicyGuid GUID | — |
Status HexInt32 | — NTSTATUS reference |
References #
Event ID 8040 — Package family name Version version GUID was prevented from installing or updating due to Config CI policy (Name:PackageFamilyName ID:PolicyNameLength Version:PolicyName GUID:PolicyIDLength).
Description
Package family name Version version GUID was prevented from installing or updating due to Config CI policy (Name:PackageFamilyName ID:PolicyNameLength Version:PolicyName GUID:PolicyIDLength). Status PolicyID.
Message #
Fields #
| Name | Description |
|---|---|
ID | — |
Version | — |
GUID | — |
PackageFamilyNameLength UInt16 | — |
PackageFamilyName UnicodeString | — |
PackageVersion UInt64 | — |
PolicyNameLength UInt16 | — |
PolicyName UnicodeString | — |
PolicyIDLength UInt16 | — |
PolicyID UnicodeString | — |
PolicyVersion UInt64 | — |
PolicyGuid GUID | — |
Status HexInt32 | — NTSTATUS reference |
References #
Event ID 8041 — A Subject was allowed to ExecutionDecision by system execution policy.
Event ID 8042 — A Subject was not allowed to be executed by system execution policy.
Event ID 8043 — Process RegisterUninstallStringEventData.ProcessName attempted to register UninstallString RegisterUninstallStringEventData.UninstallString, Status: RegisterUninstallStringEventData.Status.
#Description
Process RegisterUninstallStringEventData.ProcessName attempted to register UninstallString RegisterUninstallStringEventData.UninstallString, Status: RegisterUninstallStringEventData.Status.
Message #
Fields #
| Name | Description |
|---|---|
RegisterUninstallStringEventData.UninstallStringLength | — |
RegisterUninstallStringEventData.UninstallString | — |
RegisterUninstallStringEventData.UninstallerPathLength | — |
RegisterUninstallStringEventData.UninstallerPath | — |
RegisterUninstallStringEventData.ProcessNameLength | — |
RegisterUninstallStringEventData.ProcessName | — |
RegisterUninstallStringEventData.SessionId | — |
RegisterUninstallStringEventData.SubSessionId | — |
RegisterUninstallStringEventData.Status | 2, Status. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-AppLocker",
"guid": "CBDA4DBF-8D5D-4F69-9578-BE14AA540D22",
"event_source_name": "",
"event_id": 8043,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T01:02:05.721093+00:00",
"event_record_id": 43,
"correlation": {},
"execution": {
"process_id": 12912,
"thread_id": 13892
},
"channel": "Microsoft-Windows-AppLocker/EXE and DLL",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"user_data": {
"RegisterUninstallStringEventData": {
"UninstallStringLength": 43,
"UninstallString": "\"C:\\Program Files\\TeamViewer\\uninstall.exe\"",
"UninstallerPathLength": 53,
"UninstallerPath": "\\DosDevices\\C:\\Program Files\\TeamViewer\\uninstall.exe",
"ProcessNameLength": 78,
"ProcessName": "\\Device\\HarddiskVolume4\\Users\\User\\AppData\\Local\\Temp\\CDD35C~1\\TeamViewer_.exe",
"SessionId": "F205B252-1454-4144-BD5A-E00D8E398514",
"SubSessionId": "0A236C0E-D7AD-508F-13CB-E8248F7D7476",
"Status": 0
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8044 — Checking cmdline UninstallStringLength against registered UninstallStrings CmdlineLength, MatchFound: Cmdline, Status:MatchFound.
Description
Checking cmdline UninstallStringLength against registered UninstallStrings CmdlineLength, MatchFound: Cmdline, Status:MatchFound.
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
UninstallStringLength UInt16 | — |
UninstallString UnicodeString | — |
CmdlineLength UInt16 | — |
Cmdline UnicodeString | — |
MatchFound Boolean | — |
Event ID 8045 — Smart App Control Block Details
Description
Smart App Control Block Details.
Message #
Fields #
| Name | Description |
|---|---|
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileSha256Hash Binary | — |
DefenderScanResultDetails UInt32 | — |
DefenderClientStatusCode Int32 | — |
DefenderCloudHTTPCode HexInt32 | — |
DefenderEngineReportGUID GUID | — |
DefenderFlags Int64 | — |
DefenderCalled UInt32 | — |
DefenderCallAttempted UInt32 | — |
DefenderCloudCallRequested UInt32 | — |
DefenderMadeCloudCall UInt32 | — |
ExternalAuthorizationFlags UInt32 | — |
Event ID 8045 —
Description
Smart App Control Block Details.
Fields #
| Name | Description |
|---|---|
FilePathLength UInt16 | — |
FilePathBuffer UnicodeString | — |
FileSha256Hash Binary | — |
DefenderScanResultDetails UInt32 | — |
DefenderClientStatusCode Int32 | — |
DefenderCloudHTTPCode HexInt32 | — |
DefenderEngineReportGUID GUID | — |
DefenderFlags Int64 | — |
DefenderCalled UInt32 | — |
DefenderCallAttempted UInt32 | — |
DefenderCloudCallRequested UInt32 | — |
DefenderMadeCloudCall UInt32 | — |
ExternalAuthorizationFlags UInt32 | — |
Event ID 9000 — The application setting with ID 'AppID' and name 'SettingName' was queried.
Event ID 9001 — The application setting with ID 'AppID' and name 'SettingName' was queried, and would have a different a value if all policies were enforcing.
Description
The application setting with ID 'AppID' and name 'SettingName' was queried, and would have a different a value if all policies were enforcing. For more information, see the details tab.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | — |
SettingName UnicodeString | — |
SettingType UInt32 | — |
ValueCount UInt32 | — |
Value UnicodeString | — |
AuditValueCount UInt32 | — |
AuditValue UnicodeString | — |