System Event ID 41: Unclean reboot (Kernel-Power)
- Event ID
- 41
- Channel
- System
- Provider
- Microsoft-Windows-Kernel-Power
- Log file
- System.evtx
- Category
- System
- Default logging
- Logged by default
What event 41 means
Event 41 is written during startup, not at the moment of failure: Windows notices that the previous session never completed a clean shutdown and records what it knows. That makes it a boot-time marker for an abrupt stop, usually accompanied by 6008 from the EventLog service.
The BugcheckCode field separates the two main cases. A non-zero value is the stop code of a blue screen (in decimal; 159 is 0x9F), with BugcheckParameter1–4 giving its arguments. A value of 0 means no bugcheck was recorded: the machine lost power, was reset, or hung hard. PowerButtonTimestamp is non-zero when someone held the power button to force it off.
For an analyst, 41 bounds a gap in the logs. Anything that happened between the last record before the crash and the next boot (12) is unrecorded, and a crash right after an intrusion step (driver load, LSASS tampering, a kernel exploit) is worth correlating.
When it is logged
Always logged to the System log at the first boot after an unclean shutdown.
Level is Critical. Additional fields (SleepInProgress, ConnectedStandbyInProgress, Checkpoint, BootAppStatus) vary by Windows version.
Key fields
| Field | What it tells you |
|---|---|
| BugcheckCode | Stop code of the blue screen, in decimal. 0 means no bugcheck was captured (power loss, reset or hard hang). |
| BugcheckParameter1 | First bugcheck parameter; meaning depends on the stop code. Parameters 2–4 follow. |
| PowerButtonTimestamp | Non-zero when the power button was held to force the shutdown. |
| SleepInProgress | Non-zero when the failure happened while the system was entering or resuming from sleep. |
| ConnectedStandbyInProgress | Whether the system was in or transitioning to Modern Standby at the time. |
Common benign sources
- Power outages, laptops running out of battery, and hypervisor hard resets of VMs.
- Blue screens caused by faulty drivers or hardware.
- Users holding the power button on a frozen machine.
What attackers do that produces it
- Crashes caused by a failed kernel exploit or a vulnerable driver loaded for EDR tampering (bring your own vulnerable driver).
- Forced resets used to interrupt logging or defensive tools during an intrusion.
Investigation tips
- Read
BugcheckCode; non-zero values point to a blue screen, so check for a memory dump (MEMORY.DMP, Minidump folder). - Find the last records before the gap; driver installs (7045 with a kernel driver) or new services just before a crash are suspicious.
- Correlate with 6008 for the approximate time the previous session died.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1529 System Shutdown/Reboot | Impact |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumCertificate Use With No Strong MappingRule by @br4dy5, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.