Skip to content
Application

Application Event ID 1000: Application crash

Faulting application name, version, faulting module nameApplication event 1000 records a process crash: application, faulting module, exception code and offset. Exposes exploits and killed tools.
1000
Event ID
1000
Channel
Application
Provider
Application Error
Log file
Application.evtx
Category
Software
Default logging
Logged by default

What event 1000 means

Event 1000 is written by Windows Error Reporting's "Application Error" source when a process crashes with an unhandled exception. It names the crashing executable (AppName, AppPath), the module where the fault happened (ModuleName, ModulePath), the exception code and the offset inside the module. A matching 1001 usually follows with the WER report bucket.

Most crashes are bugs. The security-relevant ones stand out by what crashed and how: a crash of lsass.exe can follow credential-dumping or injection attempts; repeated crashes of a browser, Office application, PDF reader or network-facing service can be failed exploitation; crashes of antivirus or EDR processes can be tampering. A faulting module in a user-writable path (temp folders, AppData) inside a legitimate process points to DLL side-loading or injection.

ExceptionCode helps classify: access violations (c0000005) and stack buffer overruns (c0000409) are common in memory corruption; .NET applications report e0434352.

When it is logged

Audit policy / configuration

Always logged to the Application log when a user-mode process crashes.

Named fields (AppName, ExceptionCode...) appear on recent Windows 10/11 and Server builds; older builds store the same values as unnamed insertion strings in message order.

Key fields

FieldWhat it tells you
AppNameFile name of the crashing executable, e.g. lsass.exe, winword.exe.
AppVersionFile version of the crashing executable.
AppPathFull path of the crashing executable. Unusual locations are worth a look.
ModuleNameModule in which the fault occurred (ntdll.dll, KERNELBASE.dll, or a third-party DLL).
ModulePathFull path of the faulting module. A DLL in a user-writable folder loaded by a system process is suspicious.
ExceptionCodeException that caused the crash, in hex.
ValueMeaning
c0000005Access violation — invalid memory read or write. The most common crash and typical of memory corruption.
c0000409Stack buffer overrun / fail-fast — the process terminated itself after detecting corruption.
c0000374Heap corruption.
80000003Breakpoint reached with no debugger attached.
e0434352Unhandled .NET (CLR) exception.
FaultingOffsetOffset within the faulting module. Identical offsets across hosts suggest the same bug or exploit.
ProcessIdProcess ID of the crashed process, in hex.
IntegratorReportIdReport ID linking to the matching Windows Error Reporting 1001 record and report folder.

Common benign sources

  • Ordinary application bugs, incompatible plug-ins and out-of-memory conditions.
  • Crashes during updates when files are replaced under a running process.

What attackers do that produces it

  • lsass.exe crashes after failed credential dumping or injection attempts; an LSASS crash also forces a reboot.
  • Repeated crashes of Office, browsers, PDF readers or exposed services with the same offset: exploitation attempts.
  • Security tools (for example MsMpEng.exe) crashing after tampering or exploitation.

Investigation tips

  • Prioritize crashes of lsass.exe, security products, and document or web-facing processes.
  • Check ModulePath for DLLs outside system and program directories.
  • Correlate with process creation, network activity and file writes right before the crash; retrieve WER report files and dumps if present.
  • Match IntegratorReportId with the 1001 record to find the WER report on disk.

MITRE ATT&CK techniques

TechniqueTactics
T1203 Exploitation for Client ExecutionExecution
T1068 Exploitation for Privilege EscalationPrivilege Escalation
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading