Application Popup

1 events across 1 channel

EventTitleChannelSample
26Application popup: Caption : Message.SystemY

Event ID 26: Application popup: Caption : Message.

#
Provider
Application Popup
Channel
System
Level
Informational

Description

Application popup: Caption : Message.

Message #

Application popup: %1 : %2

Fields #

NameDescriptionRules
Caption UnicodeStringApplication popup.2 detection rules
Message UnicodeString

Example Event #

{
  "system": {
    "provider": "Application Popup",
    "guid": "47BFA2B7-BD54-4FAC-B70B-29021084CA8F",
    "event_source_name": "",
    "event_id": 26,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:30:59.302635+00:00",
    "event_record_id": 1847,
    "correlation": {},
    "execution": {
      "process_id": 656,
      "thread_id": 1476
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Caption": "VMware Tools Setup",
    "Message": "Setup needs to reboot the system in order to complete the install. Do you want to reboot now? The system will be rebooted shortly unless you cancel the reboot by answering 'No'."
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

References #

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 47bfa2b7-bd54-4fac-b70b-29021084ca8f

Defined in winsrv.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02