User32
10 events across 1 channel
Event ID 1073: The attempt by user param2 to restart/shutdown computer param1 failed
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 1074: The process param1 has initiated the param5 of computer param2 on behalf of user param7 for the following reason:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString |
Example Event #
{
"system": {
"provider": "User32",
"guid": "{B0AA8734-56F7-41CC-B2F4-DE228E98B946}",
"event_source_name": "",
"event_id": 1074,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9187343239835811840,
"time_created": "2026-06-13T05:22:28.8755699+00:00",
"event_record_id": 7349,
"correlation": {},
"execution": {
"process_id": 584,
"thread_id": 600
},
"channel": "System",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "wininit.exe (TELEMETRY-DC-C)",
"param2": "TELEMETRY-DC-C",
"param3": "No title for this reason could be found",
"param4": "0x800000ff",
"param5": "restart",
"param6": "",
"param7": "cell-c\\domainadmin"
},
"message": "The process wininit.exe (TELEMETRY-DC-C) has initiated the restart of computer TELEMETRY-DC-C on behalf of user cell-c\\domainadmin for the following reason: No title for this reason could be found\r\n Reason Code: 0x800000ff\r\n Shutdown Type: restart\r\n Comment: "
}
Detection Rules #
View all rules referencing this event →
Splunk # view in coverage
- System Shutdown or Reboot (Windows Event Log) source: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine
Event ID 1075: The last restart/shutdown request of computer param1 was aborted by user
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 1076: The reason supplied by user param6 for the last unexpected shutdown of this computer is:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString |
Example Event #
{
"system": {
"provider": "User32",
"guid": "{b0aa8734-56f7-41cc-b2f4-de228e98b946}",
"event_source_name": "User32",
"event_id": 1076,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9259400833873739776,
"time_created": "2026-03-08T22:34:36.922571+00:00",
"event_record_id": 10013,
"correlation": {},
"execution": {
"process_id": 768,
"thread_id": 876
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "Other (Unplanned)",
"param2": "0xa000000",
"param3": "",
"param4": "",
"param5": "\n",
"param6": "ludus\\domainadmin"
},
"message": ""
}
Event ID 1077: The attempt by user param2 to logoff computer param1 failed
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 2147484721: The attempt by user param2 to restart/shutdown computer param1 failed.
#Event ID 2147484722: The process param1 has initiated the ShutdownType of computer param2 on behalf of user param7 for the following reason: param3.
#Description
The process param1 has initiated the ShutdownType of computer param2 on behalf of user param7 for the following reason: param3.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString |
Example Event #
{
"system": {
"provider": "User32",
"event_id": 1074,
"level": "Information",
"task": null,
"opcode": null,
"time_created": "2026-04-23T15:32:05.4926192+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param5": "power off",
"param3": "Other (Planned)",
"param6": null,
"param1": "qemu-ga.exe",
"param4": "0x80000000",
"param7": "NT AUTHORITY\\SYSTEM",
"param2": "JD-DC01-2022"
}
}
Event ID 2147484723: The last restart/shutdown request of computer param1 was aborted by user param2.
#Event ID 2147484724: The reason supplied by user param6 for the last unexpected shutdown of this computer is: param1.
#Description
The reason supplied by user param6 for the last unexpected shutdown of this computer is: param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString |
Example Event #
{
"system": {
"provider": "User32",
"event_id": 1076,
"level": "Warning",
"task": null,
"opcode": null,
"time_created": "2026-03-14T00:03:47.6624769+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param5": null,
"param3": null,
"param6": "ludus\\domainadmin",
"param1": "Other (Unplanned)",
"param4": null,
"param2": "0xa000000"
}
}