Microsoft-Windows-AppModel-Runtime
131 events across 6 channels
Event ID 1 — Process %1 started at time %2 by parent %3 running as package %4 with executable %5 is application %6.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
CreateTime | — |
ParentProcessID | — |
PackageFullName | — |
ImageName | — |
PackageRelativeApplicationId | — |
Event ID 2 — %2: Cannot create the process for package %1 because an error was encountered.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 3 — %2: Cannot create the process for package %1 because an error was encountered while querying the fast cache.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 4 — %2: Cannot create the process for package %1 because an error was encountered while preparing the App credentials.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 5 — %2: Cannot create the process for package %1 because an error was encountered while checking the user-level package status.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 6 — %2: Cannot create the process for package %1 because an error was encountered while checking the machine-level package status.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 7 — %2: Cannot create the process for package %1 because an error was encountered while verifying the App credentials.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 8 — App %1 was terminated with error %2 because of an issue with application binary %3.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
FailedBinary | — |
Event ID 9 — App %1 was terminated with error %2 because of an issue with Windows binary %3.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
FailedBinary | — |
Event ID 11 — App %1 prevented the load of generated binary %3 due to error %2.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
FailedBinary | — |
Event ID 12 — An app prevented the load of a binary due to error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 14 — %2: Package runtime information %1 is corrupted (address=%5, size=%3, offset=%4, section=%6, processid=%7).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Size | — |
Offset | — |
HeaderAddr | — |
Section | — |
ProcessId | — |
Event ID 15 — %2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Size | — |
HeaderAddr | — |
Section | — |
ProcessId | — |
Event ID 16 — %2: Package runtime information %1 contains conflicting data (address=%5, size=%3, offset=%4, section=%6, processid=%7).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Size | — |
Offset | — |
HeaderAddr | — |
Section | — |
ProcessId | — |
Event ID 17 — %2: Package runtime information %1 contains unexpected data (address=%5, size=%3, offset=%4, section=%6, processid=%7).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Size | — |
Offset | — |
HeaderAddr | — |
Section | — |
ProcessId | — |
Event ID 18 — %2: Package runtime information %1 failed to load (processid=%3).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
ProcessId | — |
Event ID 19 — Package runtime information %1 failed to load because exception %2 occurred.
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ExceptionCode | — |
Event ID 20 — %2: Cannot create the process for package %1 because an error was encountered while loading the runtime information.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 21 — CreateAppContainerProfile failed for AppContainer %2 with error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 21
version: 0
level: 2
task: 0
opcode: 0
keywords: 2305913377957871618
time_created: '2022-04-07T16:44:41.304110+00:00'
event_record_id: 1
correlation: {}
execution:
process_id: 500
thread_id: 556
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ErrorCode: 2147942410
Context: onecore\ds\security\gina\profile\profext\appcontainer.cpp Line:1862 Usermode
Font Driver Host microsoft.windows.fontdrvhost
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 22 — DeleteAppContainerProfile failed for AppContainer %2 with error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 23 — UpdateAppContainerProfile failed for AppContainer %2 with error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 24 — CreateAppContainerProfile failed with error %1 because it was unable to create registry key %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 25 — CreateAppContainerProfile failed with error %1 because it was unable to set security on registry key %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 26 — AppContainer profile failed with error %1 because it was unable to delete registry key %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 27 — CreateAppContainerProfile failed with error %1 because it was unable to create folder %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 28 — CreateAppContainerProfile failed with error %1 because it was unable to set attributes on folder %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 29 — CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of registry key %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 30 — CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of folder %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 31 — CreateAppContainerProfile failed with error %1 because it was unable to find the users local app data folder.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 32 — AppContainer profile failed with error %1 because it was unable to delete folder %2 or its contents.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 33 — AppContainer profile failed with error %1 because it was unable to look up the AppContainer name.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 34 — AppContainer profile failed with error %1 because it was unable to look up the AppContainer display name.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 35 — CreateAppContainerProfile failed with error %1 because it was unable to register with the firewall.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 36 — End
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 36
version: 0
level: 2
task: 0
opcode: 0
keywords: 2305843009213693954
time_created: '2023-10-26T04:16:53.639661+00:00'
event_record_id: 1
correlation: {}
execution:
process_id: 684
thread_id: 748
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data:
Data:
Name: ErrorCode
Value: 2147944122
message: End
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 37 — App Container profile failed with error %1 because it was unable to register the AppContainer SID.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 38 — DeleteAppContainerProfile failed with error %1 because it was unable to unregister the AppContainer SID.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 39 — Successfully created AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 39
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693954
time_created: '2023-11-05T22:33:20.087771+00:00'
event_record_id: 251
correlation:
ActivityID: E4DB489E-1037-0002-F76B-DBE43710DA01
execution:
process_id: 4660
thread_id: 5424
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Data:
Name: AppContainerName
Value: Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy
message: The Scenario Event Mapper is configured with more than the maximum number
of context providers for the scenario with provider AppContainerName (event ID Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy). The
scenario will be ignored.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 40 — AppContainer %1 was not created because it already exists.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 40
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693954
time_created: '2023-11-06T06:25:28.239888+00:00'
event_record_id: 202
correlation: {}
execution:
process_id: 736
thread_id: 776
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Data:
Name: AppContainerName
Value: onecore\ds\security\gina\profile\profext\appcontainer.cpp Line:1850 Usermode
Font Driver Host microsoft.windows.fontdrvhost
message: The Scenario Event Mapper is configured with more than the maximum number
of end events for the scenario with provider AppContainerName (event ID onecore\ds\security\gina\profile\profext\appcontainer.cpp
Line:1850 Usermode Font Driver Host microsoft.windows.fontdrvhost). The scenario
will be ignored.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 41 — The Scenario Event Mapper is configured with more than the maximum number of providers.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 41
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693954
time_created: '2023-10-26T04:18:43.498634+00:00'
event_record_id: 5
correlation: {}
execution:
process_id: 2888
thread_id: 3124
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data:
Data:
Name: AppContainerName
Value: MPENG_9430677C-98FB-4F60-AE90-7960774C825F
message: The Scenario Event Mapper is configured with more than the maximum number
of providers. The provider AppContainerName will be ignored.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 42 — The Scenario Event Mapper is configured with an unsupported scenario.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 42
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693954
time_created: '2023-11-05T22:29:23.081725+00:00'
event_record_id: 227
correlation:
ActivityID: 59A0D65F-1037-0001-20F2-A0593710DA01
execution:
process_id: 5296
thread_id: 5800
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Data:
Name: AppContainerName
Value: Microsoft.VCLibs.140.00.UWPDesktop_8wekyb3d8bbwe
message: The Scenario Event Mapper is configured with an unsupported scenario. The
scenario for provider AppContainerName (event ID Microsoft.VCLibs.140.00.UWPDesktop_8wekyb3d8bbwe)
encountered error code %3 and will be ignored.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 43 — %2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Size | — |
HeaderAddr | — |
ApplicationUserModelId | — |
ProcessId | — |
Event ID 44 — %2: Application identity not accessible while loading package runtime information %1 (address=%4, size=%3, processid=%5).
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Size | — |
HeaderAddr | — |
ProcessId | — |
Event ID 45 — Failed with %1 while retrieving AppContainer %2 information during interaction with Restricted AppContainer.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 46 — Failed with %1 while retrieving AppContainer information during interaction with Restricted AppContainer.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 47 — Failed with %1 while retrieving AppContainer information.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 48 — Failed to create shared context object for Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 49 — Failed to activate Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 50 — Creation of Restricted AppContainer %2 failed with %1 because an invalid capability was specified.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 51 — Opening existing Restricted AppContainer %2 failed with %1 because the capabilities storage value could not be read.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 52 — Failed to create the capabilities storage value for Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 53 — The package %1 requires validation.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 54 — Modification was detected in package %1.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 55 — Failed to terminate app with package %1.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 56 — Validation of app with package %1 was successful.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 57 — Failed with %1 to retrieve the trust state of the package %2 folder.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 58 — App Integrity check failed with %1 while checking %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 59 — App Integrity terminated an application.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 60 — App Integrity check for %1 timed out.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 61 — %2: Cannot create the process for package %1 because an error was encountered while performing the integrity check.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 62 — Deployment server integrity check of package %1 failed with %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 63 — Failed with %1 retrieving AppModel Runtime group policy values.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Resource | — |
Event ID 64 — Failed with %1 validating AppModel Runtime group policy values.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Resource | — |
Event ID 65 — Failed with %1 retrieving AppModel Runtime status for package %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 66 — Failed with %1 retrieving AppModel Runtime status for package %2 for user %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
User | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 66
version: 0
level: 2
task: 0
opcode: 0
keywords: 2305843009213693953
time_created: '2022-04-07T16:53:25.460837+00:00'
event_record_id: 56
correlation: {}
execution:
process_id: 4128
thread_id: 5340
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ErrorCode: 87
PackageFullName: Windows
User: S-1-5-21-2121334350-1110938707-2888912545-500
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 67 — Failed with %1 modifying AppModel Runtime status for package %2 (current status = %4, desired status = %3).
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
DesiredStatus | — |
CurrentStatus | — |
Event ID 68 — AppModel Runtime status for package %1 successfully updated to %2 (previous status = %3).
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
DesiredStatus | — |
CurrentStatus | — |
Event ID 69 — Failed with %1 modifying AppModel Runtime status for package %2 for user %3 (clear=%4, set=%5).
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
User | — |
DesiredStatus | — |
CurrentStatus | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 69
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693953
time_created: '2022-04-07T17:04:34.316467+00:00'
event_record_id: 69
correlation:
ActivityID: DD7B0B6A-4A9E-0001-314A-7BDD9E4AD801
execution:
process_id: 5972
thread_id: 2672
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ErrorCode: 1168
PackageFullName: Microsoft.UI.Xaml.2.4_2.42007.9001.0_x64__8wekyb3d8bbwe
User: S-1-5-21-2121334350-1110938707-2888912545-500
DesiredStatus: 32
CurrentStatus: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 70 — Successfully updated AppModel Runtime status for package %1 for user %2 (clear=%3, set=%4).
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
User | — |
DesiredStatus | — |
CurrentStatus | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 70
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693953
time_created: '2022-04-07T17:04:43.551444+00:00'
event_record_id: 139
correlation:
ActivityID: DD7B0B6A-4A9E-0001-7475-7BDD9E4AD801
execution:
process_id: 5972
thread_id: 904
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
PackageFullName: MicrosoftWindows.UndockedDevKit_10.0.20348.1_neutral_neutral_cw5n1h2txyewy
User: S-1-5-21-2121334350-1110938707-2888912545-500
DesiredStatus: 0
CurrentStatus: 2048
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 71 — Failed with %1 modifying AppModel Runtime status version (context = %2).
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 72 — AppModel Runtime status version successfully updated.
Message
Event ID 73 — %2: Cannot create the process for package %1 because an error was encountered while performing the app data creation.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
ErrorMessage | — |
Event ID 74 — Package runtime information %1 failed to refresh because the following error %2 occurred in operation type %3.
Message
Fields
| Name | Description |
|---|---|
FileName | — |
ErrorCode | — |
Type | — |
ProcessId | — |
Event ID 75 — error %2: Cannot register the %1 package because the following error was encountered while opening the HKEY_USERS registry key.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ErrorCode | — |
Event ID 76 — error %4: Cannot register the %1 package because the following error was encountered while enumerating to remove the %2\%3 package family registry ...
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Key | — |
Subkey | — |
ErrorCode | — |
Event ID 77 — error %4 : Cannot register the %1 package because the following error was encountered while creating the %2\%3 package family registry key.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Key | — |
Subkey | — |
ErrorCode | — |
Event ID 78 — error %4: Cannot register the %1 package because the following error was encountered while removing the %2\%3 package family registry key.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Key | — |
Subkey | — |
ErrorCode | — |
Event ID 79 — %2: Package family %1 runtime information is corrupted.
Message
Fields
| Name | Description |
|---|---|
PackageFamilyName | — |
ErrorCode | — |
Event ID 80 — %2: Package family %1 runtime information is corrupted but we cannot repair it at this time.
Message
Fields
| Name | Description |
|---|---|
PackageFamilyName | — |
ErrorCode | — |
Event ID 81 — Failed with %1 to get IsPackageStageInPlace info from State Repository cache for package %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 101 — Creating AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 102 — Finished creating AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 103 — Deleting AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 104 — Finished deleting AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 105 — Updating AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 106 — Finished updating AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 107 — Creating firewall rules for AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 108 — Finished creating firewall rules for AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 109 — Deleting firewall rules for AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 110 — Finished deleting firewall rules for AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 111 — Creating Restricted AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 112 — Finished creating Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 113 — Deleting Restricted AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 114 — Finished deleting Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 115 — Opening Restricted AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 116 — Finished opening Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 117 — Enumerating all Restricted AppContainers for %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 118 — Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 119 — Launching process in Restricted AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 120 — Finished launching process in Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 121 — Terminating all processes in Restricted AppContainer %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 122 — Finished terminating all processes in Restricted AppContainer %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 123 — Checking package graph for %1.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 124 — Package graph check for %2 finished with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 125 — Performing app integrity check for package %1.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 126 — App integrity check for package %2 finished with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 127 — Performing runtime app integrity check for package %1.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
Event ID 128 — Runtime app integrity check for package %2 finished with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageFullName | — |
Event ID 129 — Firewall Service not running.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 130 — Updating Restricted AppContainer Capabilities %1.
Message
Fields
| Name | Description |
|---|---|
AppContainerName | — |
Event ID 131 — Finished Updating Restricted AppContainer Capabilities %2 with %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Context | — |
Event ID 201 — Created process %1 for application %4 in package %2.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
PackageName | — |
ImageName | — |
ApplicationName | — |
Message | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 201
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693956
time_created: '2023-11-06T01:55:56.247720+00:00'
event_record_id: 466
correlation: {}
execution:
process_id: 5324
thread_id: 18660
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
ProcessID: 21588
PackageName: Microsoft.WindowsNotepad_11.2307.27.0_x64__8wekyb3d8bbwe
ImageName: Notepad.exe
ApplicationName: Microsoft.WindowsNotepad_8wekyb3d8bbwe!App
Message: '[FinishPackageActivation]'
message: ''
Sigma Rules
- Sysinternals Tools AppX Versions Execution
Detects execution of Sysinternals tools via an AppX package. Attackers could install the Sysinternals Suite to get access to tools such as psexec and procdump to avoid detection based on System paths.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 202 — %4: Cannot create the process for package %1 because an error was encountered.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 203 — %4: Cannot create the process for package %1 because an error was encountered while preparing for activation.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 204 — %4: Cannot create the process for package %1 because an error was encountered while elevating the token.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 205 — %4: Cannot create the process for package %1 because UI Access is not supported for Desktop AppX processes.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 206 — %4: Cannot create the process for package %1 because an error was encountered while adjusting the token.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 207 — %4: Cannot create the process for package %1 because an error was encountered while launching.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 208 — %4: Cannot create the process for package %1 because an error was encountered while configuring runtime.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 209 — %4: Cannot create the process for package %1 because an error was encountered while resuming the thread.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 210 — Intel TXT SENTER time: MicrosoftWindows.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ContainerName | — |
ContainerId | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 210
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693960
time_created: '2023-11-05T22:32:34.540536+00:00'
event_record_id: 239
correlation:
ActivityID: E4DB489E-1037-0003-2157-DBE43710DA01
execution:
process_id: 920
thread_id: 472
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PackageName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
ContainerName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy-S-1-5-21-1992711665-1655669231-58201500-1000
ContainerId: '{22A04431-7C2B-11EE-936C-000C293379BA}'
message: 'Intel TXT SENTER time: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
ms.'
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 211 — Added process 6212 to Desktop AppX container {22A04431-7C2B-11EE-936C-000C293379BA} for package MicrosoftWindows.
Message
Fields
| Name | Description |
|---|---|
ProcessID | — |
PackageName | — |
ContainerId | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 211
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693960
time_created: '2023-11-05T22:32:34.540594+00:00'
event_record_id: 240
correlation:
ActivityID: E4DB489E-1037-0003-2157-DBE43710DA01
execution:
process_id: 920
thread_id: 472
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
ProcessID: 6212
PackageName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
ContainerId: '{22A04431-7C2B-11EE-936C-000C293379BA}'
message: Added process 6212 to Desktop AppX container {22A04431-7C2B-11EE-936C-000C293379BA}
for package MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 212 — %1: Cannot add process %2 to Desktop AppX container %4 for package %3 because an error was encountered.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ProcessID | — |
PackageName | — |
ContainerId | — |
Event ID 213 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the job.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageName | — |
ContainerName | — |
Event ID 214 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the description.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageName | — |
ContainerName | — |
Event ID 215 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered converting the job.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageName | — |
ContainerName | — |
Event ID 216 — %1: Cannot create the Desktop AppX container for package %2 because an error was encountered configuring the runtime.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
PackageName | — |
ContainerName | — |
Event ID 217 — Soft reboot complete prepare finished: MicrosoftWindows.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ContainerId | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: F1EF270A-0D32-4352-BA52-DBAB41E1D859
event_source_name: ''
event_id: 217
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693960
time_created: '2023-11-05T22:31:32.531960+00:00'
event_record_id: 236
correlation:
ActivityID: 59A0D65F-1037-0002-A9F7-A0593710DA01
execution:
process_id: 928
thread_id: 6576
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PackageName: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy
ContainerId: '{975E2192-7C2A-11EE-936B-000C293379BA}'
message: 'Soft reboot complete prepare finished: MicrosoftWindows.Client.WebExperience_423.23500.0.0_x64__cw5n1h2txyewy.'
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 218 — Cannot destroy Desktop AppX container %2 for package %1.
Message
Fields
| Name | Description |
|---|---|
CleanupContainerErrorCode | — |
MakeTemporaryErrorCode | — |
PackageName | — |
ContainerId | — |
Event ID 219 — PSMFlags for Desktop AppX process %1 with applicationID %2 is %3.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
ApplicationId | — |
PsmFlags | — |
Example Event
system:
provider: Microsoft-Windows-AppModel-Runtime
guid: '{f1ef270a-0d32-4352-ba52-dbab41e1d859}'
event_source_name: ''
event_id: 219
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693956
time_created: '2023-11-06T01:55:55.914607+00:00'
event_record_id: 463
correlation: {}
execution:
process_id: 5324
thread_id: 18660
channel: Microsoft-Windows-AppModel-Runtime/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 220 —
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |
Event ID 220 — Cannot start the process %2 because the executable was not found the package %1.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
ImageName | — |
ApplicationName | — |
ErrorCode | — |
Message | — |