Application Event ID 1001: Windows Error Reporting report
- Event ID
- 1001
- Channel
- Application
- Provider
- Windows Error Reporting
- Log file
- Application.evtx
- Category
- Software
- Default logging
- Logged by default
What event 1001 means
Event 1001 is logged by the Windows Error Reporting (WER) source whenever a problem report is created or processed — application crashes and hangs, kernel crashes, and many Windows diagnostics. The event name tells you the kind of report: APPCRASH for an application crash, BEX / BEX64 for crashes detected by buffer overrun or DEP protections, AppHangB1 for hangs, BlueScreen for a kernel bugcheck, plus many product-specific names.
The report parameters (P1–P10) depend on the event type; for APPCRASH they carry the application name and version, the faulting module and the exception code, repeating the data of the matching 1000. The report also lists attached files and the StorePath folder under C:\ProgramData\Microsoft\Windows\WER\ where the report — and sometimes a memory dump — was stored.
For a responder, 1001 is the pointer to evidence on disk: WER report folders can survive long after the crash and may contain dumps of the crashed process. BEX events are notable because they come from exploit mitigations firing.
When it is logged
Always logged to the Application log when WER creates or queues a report.
On many builds the data is a set of unnamed insertion strings; this viewer shows them joined in Data1. Volume varies a lot with the number of diagnostic reports.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Insertion strings in message order — fault bucket, bucket type, event name (e.g. APPCRASH), response, CAB ID, parameters P1 to P10, attached files, store path, analysis symbol, rechecking flag, report ID, report status and hashed bucket. |
Common benign sources
- Routine application crashes and hangs, driver and update diagnostics.
- Many non-crash reports (e.g. network diagnostics, update telemetry) using the same event.
What attackers do that produces it
BEX/BEX64reports for Office, browsers or services: exploit mitigations stopped a memory corruption attempt.- Crash reports for
lsass.exeor security products after tampering. - WER itself abused to dump process memory (for example LSASS via
WerFault.execommand lines) may leave related reports and dump files.
Investigation tips
- Filter on event names
APPCRASH,BEX,BEX64andBlueScreenfirst. - Read the
StorePathand collect the WER folder (Report.wer and any .dmp files) from the host. - Correlate with the matching 1000 and with process activity just before the crash.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighMicrosoft Malware Protection Engine Crash - WERRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.