System Event ID 12: Operating system started
- Event ID
- 12
- Channel
- System
- Provider
- Microsoft-Windows-Kernel-General
- Log file
- System.evtx
- Category
- System
- Default logging
- Logged by default
What event 12 means
Event 12 is written by the kernel early in every boot. It is the most precise boot marker in the System log: StartTime is the moment the kernel started, usually a few seconds before the first records of the new session, and the event also carries the OS version numbers (MajorVersion, MinorVersion, BuildVersion, QfeVersion).
Use it with its counterpart 13 (operating system shutting down) to split the log into power-on periods. A 12 that is not preceded by a 13 means the previous session ended without a clean shutdown; expect 41 (Kernel-Power) and 6008 (unexpected shutdown) around it. The EventLog service adds 6005 a few seconds later, when logging itself restarts.
Boot times matter in an investigation: changes that only take effect after a reboot (new services, drivers, boot-start persistence) show up right after a 12, and a reboot the user did not ask for can be the attacker restarting the host.
When it is logged
Always logged to the System log; no configuration needed.
BuildVersion and QfeVersion change after cumulative updates, so a sequence of 12 events also shows when the host was patched.
Key fields
| Field | What it tells you |
|---|---|
| StartTime | UTC time at which the kernel started. More precise than the record timestamp. |
| MajorVersion | Major OS version (10 for Windows 10, Windows 11 and Server 2016 and later). |
| MinorVersion | Minor OS version. |
| BuildVersion | OS build number, e.g. 19045 or 22631. Identifies the Windows release. |
| QfeVersion | Update revision of the build (the number after the dot in 19045.xxxx). |
| BootMode | Boot mode reported by the kernel; 0 on a normal boot. |
Common benign sources
- Every normal start, including restarts after Windows Update.
- Virtual machines powered on, resumed from a saved state with a reboot, or cloned.
What attackers do that produces it
- A reboot forced by an attacker to load a boot-start driver or service installed just before (look for 7045 in the minutes before the previous shutdown).
- A reboot in the middle of an intrusion that coincides with destructive activity such as ransomware or wiping.
Investigation tips
- Pair every 12 with the preceding 13 and 1074 to learn who or what requested the restart.
- A 12 without a preceding 13 points to a crash or power loss; check 41 and 6008.
- Build all activity windows between 12 and 13 before reasoning about gaps in other logs.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1529 System Shutdown/Reboot | Impact |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.