Application Popup
1 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 26 | Application popup: Caption : Message. | System | Y |
Event ID 26: Application popup: Caption : Message.
#Description
Application popup: Caption : Message.
Message #
Fields #
| Name | Description | Rules |
|---|---|---|
Caption UnicodeString | Application popup. | 2 detection rules |
Message UnicodeString |
Example Event #
{
"system": {
"provider": "Application Popup",
"guid": "47BFA2B7-BD54-4FAC-B70B-29021084CA8F",
"event_source_name": "",
"event_id": 26,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:30:59.302635+00:00",
"event_record_id": 1847,
"correlation": {},
"execution": {
"process_id": 656,
"thread_id": 1476
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Caption": "VMware Tools Setup",
"Message": "Setup needs to reboot the system in order to complete the install. Do you want to reboot now? The system will be rebooted shortly unless you cancel the reboot by answering 'No'."
},
"message": ""
}
Detection Rules #
View all rules referencing this event →Sigma # view in coverage
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 47bfa2b7-bd54-4fac-b70b-29021084ca8f
Defined in winsrv.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02