Application Popup
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 26 | Application popup: Caption : Message. | System | Y | Y |
Event ID 26: Application popup: Caption : Message.
#Message #
Fields #
| Name | Description | Rules |
|---|---|---|
Caption UnicodeString | Application popup. | 2 detection rules |
Message UnicodeString |
Example Event #
{
"system": {
"provider": "Application Popup",
"guid": "47BFA2B7-BD54-4FAC-B70B-29021084CA8F",
"event_source_name": "",
"event_id": 26,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:30:59.302635+00:00",
"event_record_id": 1847,
"correlation": {},
"execution": {
"process_id": 656,
"thread_id": 1476
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Caption": "VMware Tools Setup",
"Message": "Setup needs to reboot the system in order to complete the install. Do you want to reboot now? The system will be rebooted shortly unless you cancel the reboot by answering 'No'."
},
"message": ""
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma # view in coverage
T1685
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Provenance
ETW provider GUID 47bfa2b7-bd54-4fac-b70b-29021084ca8f
Defined in winsrv.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02