AppLocker Event ID 8002: EXE or DLL allowed
- Event ID
- 8002
- Channel
- Microsoft-Windows-AppLocker/EXE and DLL
- Provider
- Microsoft-Windows-AppLocker
- Log file
- Microsoft-Windows-AppLocker%4EXE and DLL.evtx
- Category
- Application control
- Default logging
- Needs configuration
What event 8002 means
Event 8002 is written to the AppLocker EXE and DLL log when an executable (or, if DLL rules are enabled, a DLL) is evaluated against the policy and allowed by a rule. The data sits under UserData/RuleAndFileData: the rule collection (PolicyName), the rule that matched (RuleId, RuleName), the user (TargetUser, TargetLogonId), the file (FilePath, FullFilePath, FileHash, Fqbn) and the process ID.
Because every allowed launch is logged, 8002 works as a lightweight execution history on hosts with AppLocker, including the signer (Fqbn) and hash of each binary — useful where Sysmon or process creation auditing is missing.
The flip side is volume, especially with DLL rules. The value lies in rare paths and in broad allow rules: a file from a user-writable folder allowed by a path rule such as "all files in the Windows folder" can indicate a bypass through a writable subdirectory.
When it is logged
An AppLocker policy with Executable (and optionally DLL) rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged for allowed files in both Audit only and Enforce rules modes.
DLL rules are off unless enabled in the policy's advanced settings, and they add significant volume. Microsoft notes the EXE and DLL log is very verbose; many collectors keep only warnings and errors from it. AppLocker enforcement depends on the Windows edition; unsupported editions log 8008 instead.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| PolicyName | Rule collection that evaluated the file.
| ||||||
| RuleId | GUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny. | ||||||
| RuleName | Name of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched. | ||||||
| RuleSddl | Security descriptor of the rule, showing which user or group SID the rule applies to. | ||||||
| TargetUser | SID of the user who tried to run the file. | ||||||
| TargetProcessId | ID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1. | ||||||
| TargetLogonId | Logon session of the user; pivot to Security 4624 and 4688 with the same logon ID. | ||||||
| FilePath | Path of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\.... | ||||||
| FullFilePath | The same path in plain form (C:\Users\...). Present on current Windows versions. | ||||||
| FileHash | AppLocker hash of the file, used by file hash rules. | ||||||
| Fqbn | Fully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files. |
Common benign sources
- Normal program launches allowed by publisher, path or hash rules — the bulk of this log.
- Software updates running from
Program FilesorWindowsunder the default rules.
What attackers do that produces it
- Payloads executed from writable folders under
C:\Windows(for exampleTasksorTemp) that are allowed by default path rules. - Signed living-off-the-land binaries (
mshta.exe,rundll32.exe,regsvr32.exe,msbuild.exe) allowed by broad rules and used to proxy execution.
Investigation tips
- Stack FullFilePath and Fqbn; review rare paths, unsigned files and files allowed by broad path rules.
- Pivot on TargetLogonId and TargetProcessId to Security 4624/4688 or Sysmon 1 for the session and command line.
- Compare with 8003/8004 in the same log to see what the policy did not allow.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1218 System Binary Proxy Execution | Stealth |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.