Skip to content
Application

Application Event ID 1001: Windows Error Reporting report

Fault bucket, type, event name, responseApplication event 1001 records a Windows Error Reporting report (APPCRASH, BEX, BlueScreen...) and its report folder. Complements 1000.
1001
Event ID
1001
Channel
Application
Provider
Windows Error Reporting
Log file
Application.evtx
Category
Software
Default logging
Logged by default

What event 1001 means

Event 1001 is logged by the Windows Error Reporting (WER) source whenever a problem report is created or processed — application crashes and hangs, kernel crashes, and many Windows diagnostics. The event name tells you the kind of report: APPCRASH for an application crash, BEX / BEX64 for crashes detected by buffer overrun or DEP protections, AppHangB1 for hangs, BlueScreen for a kernel bugcheck, plus many product-specific names.

The report parameters (P1–P10) depend on the event type; for APPCRASH they carry the application name and version, the faulting module and the exception code, repeating the data of the matching 1000. The report also lists attached files and the StorePath folder under C:\ProgramData\Microsoft\Windows\WER\ where the report — and sometimes a memory dump — was stored.

For a responder, 1001 is the pointer to evidence on disk: WER report folders can survive long after the crash and may contain dumps of the crashed process. BEX events are notable because they come from exploit mitigations firing.

When it is logged

Audit policy / configuration

Always logged to the Application log when WER creates or queues a report.

On many builds the data is a set of unnamed insertion strings; this viewer shows them joined in Data1. Volume varies a lot with the number of diagnostic reports.

Key fields

FieldWhat it tells you
Data1Insertion strings in message order — fault bucket, bucket type, event name (e.g. APPCRASH), response, CAB ID, parameters P1 to P10, attached files, store path, analysis symbol, rechecking flag, report ID, report status and hashed bucket.

Common benign sources

  • Routine application crashes and hangs, driver and update diagnostics.
  • Many non-crash reports (e.g. network diagnostics, update telemetry) using the same event.

What attackers do that produces it

  • BEX / BEX64 reports for Office, browsers or services: exploit mitigations stopped a memory corruption attempt.
  • Crash reports for lsass.exe or security products after tampering.
  • WER itself abused to dump process memory (for example LSASS via WerFault.exe command lines) may leave related reports and dump files.

Investigation tips

  • Filter on event names APPCRASH, BEX, BEX64 and BlueScreen first.
  • Read the StorePath and collect the WER folder (Report.wer and any .dmp files) from the host.
  • Correlate with the matching 1000 and with process activity just before the crash.

MITRE ATT&CK techniques

TechniqueTactics
T1203 Exploitation for Client ExecutionExecution
T1003.001 OS Credential Dumping: LSASS MemoryCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading