Skip to content
AppLocker

AppLocker Event ID 8003: EXE or DLL would be blocked (audit)

File was allowed to run but would have been prevented from running if the AppLocker policy were enforcedAppLocker event 8003 records an executable or DLL that ran but would have been blocked if the policy were enforced. Audit-mode view of unapproved code.
8003
Event ID
8003
Channel
Microsoft-Windows-AppLocker/EXE and DLL
Provider
Microsoft-Windows-AppLocker
Log file
Microsoft-Windows-AppLocker%4EXE and DLL.evtx
Category
Application control
Default logging
Needs configuration

What event 8003 means

Event 8003 is written to the AppLocker EXE and DLL log when the rule collection is in Audit only mode and a file that no allow rule covers (or that a deny rule matches) is executed. The program still runs; the event records what enforcement would have stopped.

Organizations often leave AppLocker in audit mode for long periods, which turns 8003 into an inventory of everything outside the approved baseline. For an investigator that is valuable: malware and attacker tools dropped in user profiles, temp folders or downloads are exactly the files that fall outside a typical policy.

The fields are the same as 8002 and 8004: PolicyName, RuleId/RuleName (zero GUID and - when no rule matched), TargetUser, TargetLogonId, FilePath, FullFilePath, FileHash and Fqbn.

When it is logged

Audit policy / configuration

An AppLocker policy with Executable (and optionally DLL) rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged only when the rule collection is in Audit only mode.

DLL rules are off unless enabled in the policy's advanced settings, and they add significant volume. Microsoft notes the EXE and DLL log is very verbose; many collectors keep only warnings and errors from it. AppLocker enforcement depends on the Windows edition; unsupported editions log 8008 instead.

Key fields

FieldWhat it tells you
PolicyNameRule collection that evaluated the file.
ValueMeaning
EXEExecutable rules (.exe and .com).
DLLDLL rules (.dll and .ocx) — only evaluated when DLL rule enforcement is turned on.
RuleIdGUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny.
RuleNameName of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched.
RuleSddlSecurity descriptor of the rule, showing which user or group SID the rule applies to.
TargetUserSID of the user who tried to run the file.
TargetProcessIdID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1.
TargetLogonIdLogon session of the user; pivot to Security 4624 and 4688 with the same logon ID.
FilePathPath of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\....
FullFilePathThe same path in plain form (C:\Users\...). Present on current Windows versions.
FileHashAppLocker hash of the file, used by file hash rules.
FqbnFully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files.

Common benign sources

  • Legitimate software not yet covered by rules during an audit rollout (per-user installers, portable tools).
  • Developer and admin tools run from user profiles.

What attackers do that produces it

  • Malware and tools executed from AppData, Temp, Downloads or ProgramData.
  • Renamed or unsigned binaries that would be blocked once the policy is enforced.

Investigation tips

  • Review files outside Program Files and Windows, unsigned files (Fqbn -) and first-seen hashes.
  • Pivot on TargetLogonId / TargetProcessId to the logon and process creation events for context.
  • Check the file hash against threat intelligence and look for the same file on other hosts.

MITRE ATT&CK techniques

TechniqueTactics
T1204.002 User Execution: Malicious FileExecution
T1036.005 Masquerading: Match Legitimate Resource Name or LocationStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideAppLocker event logs: 8003, 8004 and what ran

Sources and further reading