Application Popup

EventTitleChannelSampleRule
26Application popup: Caption : Message.SystemYY

Event ID 26: Application popup: Caption : Message.

#
Channel
System
Level
Informational

Message #

Application popup: %1 : %2

Fields #

NameDescriptionRules
Caption UnicodeStringApplication popup.2 detection rules
Message UnicodeString

Example Event #

{
  "system": {
    "provider": "Application Popup",
    "guid": "47BFA2B7-BD54-4FAC-B70B-29021084CA8F",
    "event_source_name": "",
    "event_id": 26,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:30:59.302635+00:00",
    "event_record_id": 1847,
    "correlation": {},
    "execution": {
      "process_id": 656,
      "thread_id": 1476
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Caption": "VMware Tools Setup",
    "Message": "Setup needs to reboot the system in order to complete the install. Do you want to reboot now? The system will be rebooted shortly unless you cancel the reboot by answering 'No'."
  },
  "message": ""
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Provenance

ETW provider GUID 47bfa2b7-bd54-4fac-b70b-29021084ca8f

Defined in winsrv.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02