Application Event ID 1000: Application crash
- Event ID
- 1000
- Channel
- Application
- Provider
- Application Error
- Log file
- Application.evtx
- Category
- Software
- Default logging
- Logged by default
What event 1000 means
Event 1000 is written by Windows Error Reporting's "Application Error" source when a process crashes with an unhandled exception. It names the crashing executable (AppName, AppPath), the module where the fault happened (ModuleName, ModulePath), the exception code and the offset inside the module. A matching 1001 usually follows with the WER report bucket.
Most crashes are bugs. The security-relevant ones stand out by what crashed and how: a crash of lsass.exe can follow credential-dumping or injection attempts; repeated crashes of a browser, Office application, PDF reader or network-facing service can be failed exploitation; crashes of antivirus or EDR processes can be tampering. A faulting module in a user-writable path (temp folders, AppData) inside a legitimate process points to DLL side-loading or injection.
ExceptionCode helps classify: access violations (c0000005) and stack buffer overruns (c0000409) are common in memory corruption; .NET applications report e0434352.
When it is logged
Always logged to the Application log when a user-mode process crashes.
Named fields (AppName, ExceptionCode...) appear on recent Windows 10/11 and Server builds; older builds store the same values as unnamed insertion strings in message order.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AppName | File name of the crashing executable, e.g. lsass.exe, winword.exe. | ||||||||||||
| AppVersion | File version of the crashing executable. | ||||||||||||
| AppPath | Full path of the crashing executable. Unusual locations are worth a look. | ||||||||||||
| ModuleName | Module in which the fault occurred (ntdll.dll, KERNELBASE.dll, or a third-party DLL). | ||||||||||||
| ModulePath | Full path of the faulting module. A DLL in a user-writable folder loaded by a system process is suspicious. | ||||||||||||
| ExceptionCode | Exception that caused the crash, in hex.
| ||||||||||||
| FaultingOffset | Offset within the faulting module. Identical offsets across hosts suggest the same bug or exploit. | ||||||||||||
| ProcessId | Process ID of the crashed process, in hex. | ||||||||||||
| IntegratorReportId | Report ID linking to the matching Windows Error Reporting 1001 record and report folder. |
Common benign sources
- Ordinary application bugs, incompatible plug-ins and out-of-memory conditions.
- Crashes during updates when files are replaced under a running process.
What attackers do that produces it
lsass.execrashes after failed credential dumping or injection attempts; an LSASS crash also forces a reboot.- Repeated crashes of Office, browsers, PDF readers or exposed services with the same offset: exploitation attempts.
- Security tools (for example
MsMpEng.exe) crashing after tampering or exploitation.
Investigation tips
- Prioritize crashes of
lsass.exe, security products, and document or web-facing processes. - Check
ModulePathfor DLLs outside system and program directories. - Correlate with process creation, network activity and file writes right before the crash; retrieve WER report files and dumps if present.
- Match
IntegratorReportIdwith the 1001 record to find the WER report on disk.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- HighLSASS Process Crashed - ApplicationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighMicrosoft Malware Protection Engine CrashRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.