Skip to content
AppLocker

AppLocker Event ID 8002: EXE or DLL allowed

File was allowed to runAppLocker event 8002 records that an executable or DLL was allowed to run by an AppLocker rule, with the file path, matching rule and user SID.
8002
Event ID
8002
Channel
Microsoft-Windows-AppLocker/EXE and DLL
Provider
Microsoft-Windows-AppLocker
Log file
Microsoft-Windows-AppLocker%4EXE and DLL.evtx
Category
Application control
Default logging
Needs configuration

What event 8002 means

Event 8002 is written to the AppLocker EXE and DLL log when an executable (or, if DLL rules are enabled, a DLL) is evaluated against the policy and allowed by a rule. The data sits under UserData/RuleAndFileData: the rule collection (PolicyName), the rule that matched (RuleId, RuleName), the user (TargetUser, TargetLogonId), the file (FilePath, FullFilePath, FileHash, Fqbn) and the process ID.

Because every allowed launch is logged, 8002 works as a lightweight execution history on hosts with AppLocker, including the signer (Fqbn) and hash of each binary — useful where Sysmon or process creation auditing is missing.

The flip side is volume, especially with DLL rules. The value lies in rare paths and in broad allow rules: a file from a user-writable folder allowed by a path rule such as "all files in the Windows folder" can indicate a bypass through a writable subdirectory.

When it is logged

Audit policy / configuration

An AppLocker policy with Executable (and optionally DLL) rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged for allowed files in both Audit only and Enforce rules modes.

DLL rules are off unless enabled in the policy's advanced settings, and they add significant volume. Microsoft notes the EXE and DLL log is very verbose; many collectors keep only warnings and errors from it. AppLocker enforcement depends on the Windows edition; unsupported editions log 8008 instead.

Key fields

FieldWhat it tells you
PolicyNameRule collection that evaluated the file.
ValueMeaning
EXEExecutable rules (.exe and .com).
DLLDLL rules (.dll and .ocx) — only evaluated when DLL rule enforcement is turned on.
RuleIdGUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny.
RuleNameName of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched.
RuleSddlSecurity descriptor of the rule, showing which user or group SID the rule applies to.
TargetUserSID of the user who tried to run the file.
TargetProcessIdID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1.
TargetLogonIdLogon session of the user; pivot to Security 4624 and 4688 with the same logon ID.
FilePathPath of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\....
FullFilePathThe same path in plain form (C:\Users\...). Present on current Windows versions.
FileHashAppLocker hash of the file, used by file hash rules.
FqbnFully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files.

Common benign sources

  • Normal program launches allowed by publisher, path or hash rules — the bulk of this log.
  • Software updates running from Program Files or Windows under the default rules.

What attackers do that produces it

  • Payloads executed from writable folders under C:\Windows (for example Tasks or Temp) that are allowed by default path rules.
  • Signed living-off-the-land binaries (mshta.exe, rundll32.exe, regsvr32.exe, msbuild.exe) allowed by broad rules and used to proxy execution.

Investigation tips

  • Stack FullFilePath and Fqbn; review rare paths, unsigned files and files allowed by broad path rules.
  • Pivot on TargetLogonId and TargetProcessId to Security 4624/4688 or Sysmon 1 for the session and command line.
  • Compare with 8003/8004 in the same log to see what the policy did not allow.

MITRE ATT&CK techniques

TechniqueTactics
T1218 System Binary Proxy ExecutionStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading