Skip to content
System

System Event ID 12: Operating system started

The operating system started at system timeSystem event 12 (Kernel-General) marks an operating system boot and records the exact kernel start time and OS build. The anchor for every boot timeline.
12
Event ID
12
Channel
System
Provider
Microsoft-Windows-Kernel-General
Log file
System.evtx
Category
System
Default logging
Logged by default

What event 12 means

Event 12 is written by the kernel early in every boot. It is the most precise boot marker in the System log: StartTime is the moment the kernel started, usually a few seconds before the first records of the new session, and the event also carries the OS version numbers (MajorVersion, MinorVersion, BuildVersion, QfeVersion).

Use it with its counterpart 13 (operating system shutting down) to split the log into power-on periods. A 12 that is not preceded by a 13 means the previous session ended without a clean shutdown; expect 41 (Kernel-Power) and 6008 (unexpected shutdown) around it. The EventLog service adds 6005 a few seconds later, when logging itself restarts.

Boot times matter in an investigation: changes that only take effect after a reboot (new services, drivers, boot-start persistence) show up right after a 12, and a reboot the user did not ask for can be the attacker restarting the host.

When it is logged

Audit policy / configuration

Always logged to the System log; no configuration needed.

BuildVersion and QfeVersion change after cumulative updates, so a sequence of 12 events also shows when the host was patched.

Key fields

FieldWhat it tells you
StartTimeUTC time at which the kernel started. More precise than the record timestamp.
MajorVersionMajor OS version (10 for Windows 10, Windows 11 and Server 2016 and later).
MinorVersionMinor OS version.
BuildVersionOS build number, e.g. 19045 or 22631. Identifies the Windows release.
QfeVersionUpdate revision of the build (the number after the dot in 19045.xxxx).
BootModeBoot mode reported by the kernel; 0 on a normal boot.

Common benign sources

  • Every normal start, including restarts after Windows Update.
  • Virtual machines powered on, resumed from a saved state with a reboot, or cloned.

What attackers do that produces it

  • A reboot forced by an attacker to load a boot-start driver or service installed just before (look for 7045 in the minutes before the previous shutdown).
  • A reboot in the middle of an intrusion that coincides with destructive activity such as ransomware or wiping.

Investigation tips

  • Pair every 12 with the preceding 13 and 1074 to learn who or what requested the restart.
  • A 12 without a preceding 13 points to a crash or power loss; check 41 and 6008.
  • Build all activity windows between 12 and 13 before reasoning about gaps in other logs.

MITRE ATT&CK techniques

TechniqueTactics
T1529 System Shutdown/RebootImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading