AppLocker Event ID 8004: EXE or DLL blocked
- Event ID
- 8004
- Channel
- Microsoft-Windows-AppLocker/EXE and DLL
- Provider
- Microsoft-Windows-AppLocker
- Log file
- Microsoft-Windows-AppLocker%4EXE and DLL.evtx
- Category
- Application control
- Default logging
- Needs configuration
What event 8004 means
Event 8004 is written to the AppLocker EXE and DLL log when a rule collection is in Enforce rules mode and a file is denied — either by an explicit deny rule or because no allow rule covers it. The execution did not happen.
A block is both a success and a signal: something tried to run code outside the approved baseline. On well-managed hosts, 8004 events are rare enough to review individually. Clusters of blocks from user-writable folders shortly after a phishing email, a download or a new logon are a classic early indicator of intrusion.
Remember that the attacker may have tried again with another technique. Look around the block for allowed executions (8002), script activity (8005–8007) and process creation for signs of a successful workaround.
When it is logged
An AppLocker policy with Executable (and optionally DLL) rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged only when the rule collection is in Enforce rules mode.
DLL rules are off unless enabled in the policy's advanced settings, and they add significant volume. Microsoft notes the EXE and DLL log is very verbose; many collectors keep only warnings and errors from it. AppLocker enforcement depends on the Windows edition; unsupported editions log 8008 instead.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| PolicyName | Rule collection that evaluated the file.
| ||||||
| RuleId | GUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny. | ||||||
| RuleName | Name of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched. | ||||||
| RuleSddl | Security descriptor of the rule, showing which user or group SID the rule applies to. | ||||||
| TargetUser | SID of the user who tried to run the file. | ||||||
| TargetProcessId | ID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1. | ||||||
| TargetLogonId | Logon session of the user; pivot to Security 4624 and 4688 with the same logon ID. | ||||||
| FilePath | Path of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\.... | ||||||
| FullFilePath | The same path in plain form (C:\Users\...). Present on current Windows versions. | ||||||
| FileHash | AppLocker hash of the file, used by file hash rules. | ||||||
| Fqbn | Fully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files. |
Common benign sources
- Users trying to run unapproved software, portable apps or installers from their profile.
- Legitimate updates that change a file path or signer not yet covered by the rules.
What attackers do that produces it
- Blocked execution of malware dropped by phishing attachments or downloads into
AppData,TemporDownloads. - Attacker tools copied to a host during lateral movement and blocked on execution.
Investigation tips
- Review every 8004 on servers and sensitive hosts; on workstations, prioritize user-writable paths and unsigned files.
- Pivot on TargetLogonId to Security 4624 to see how the user was logged on (interactive, RDP, network).
- Look for follow-up attempts that succeeded (8002, 8005, LOLBins in Security 4688 or Sysmon 1).
- Collect the blocked file by FullFilePath and FileHash for analysis.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumAppLocker Prevented Application or Script from RunningRule by Pushkarev Dmitry, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.