Skip to content
AppLocker

AppLocker Event ID 8004: EXE or DLL blocked

File was prevented from runningAppLocker event 8004 records an executable or DLL blocked by an enforced AppLocker policy, with file path, signer, hash and the user who tried to run it.
8004
Event ID
8004
Channel
Microsoft-Windows-AppLocker/EXE and DLL
Provider
Microsoft-Windows-AppLocker
Log file
Microsoft-Windows-AppLocker%4EXE and DLL.evtx
Category
Application control
Default logging
Needs configuration

What event 8004 means

Event 8004 is written to the AppLocker EXE and DLL log when a rule collection is in Enforce rules mode and a file is denied — either by an explicit deny rule or because no allow rule covers it. The execution did not happen.

A block is both a success and a signal: something tried to run code outside the approved baseline. On well-managed hosts, 8004 events are rare enough to review individually. Clusters of blocks from user-writable folders shortly after a phishing email, a download or a new logon are a classic early indicator of intrusion.

Remember that the attacker may have tried again with another technique. Look around the block for allowed executions (8002), script activity (8005–8007) and process creation for signs of a successful workaround.

When it is logged

Audit policy / configuration

An AppLocker policy with Executable (and optionally DLL) rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged only when the rule collection is in Enforce rules mode.

DLL rules are off unless enabled in the policy's advanced settings, and they add significant volume. Microsoft notes the EXE and DLL log is very verbose; many collectors keep only warnings and errors from it. AppLocker enforcement depends on the Windows edition; unsupported editions log 8008 instead.

Key fields

FieldWhat it tells you
PolicyNameRule collection that evaluated the file.
ValueMeaning
EXEExecutable rules (.exe and .com).
DLLDLL rules (.dll and .ocx) — only evaluated when DLL rule enforcement is turned on.
RuleIdGUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny.
RuleNameName of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched.
RuleSddlSecurity descriptor of the rule, showing which user or group SID the rule applies to.
TargetUserSID of the user who tried to run the file.
TargetProcessIdID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1.
TargetLogonIdLogon session of the user; pivot to Security 4624 and 4688 with the same logon ID.
FilePathPath of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\....
FullFilePathThe same path in plain form (C:\Users\...). Present on current Windows versions.
FileHashAppLocker hash of the file, used by file hash rules.
FqbnFully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files.

Common benign sources

  • Users trying to run unapproved software, portable apps or installers from their profile.
  • Legitimate updates that change a file path or signer not yet covered by the rules.

What attackers do that produces it

  • Blocked execution of malware dropped by phishing attachments or downloads into AppData, Temp or Downloads.
  • Attacker tools copied to a host during lateral movement and blocked on execution.

Investigation tips

  • Review every 8004 on servers and sensitive hosts; on workstations, prioritize user-writable paths and unsigned files.
  • Pivot on TargetLogonId to Security 4624 to see how the user was logged on (interactive, RDP, network).
  • Look for follow-up attempts that succeeded (8002, 8005, LOLBins in Security 4688 or Sysmon 1).
  • Collect the blocked file by FullFilePath and FileHash for analysis.

MITRE ATT&CK techniques

TechniqueTactics
T1204.002 User Execution: Malicious FileExecution
T1036.005 Masquerading: Match Legitimate Resource Name or LocationStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideAppLocker event logs: 8003, 8004 and what ran

Sources and further reading