Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll

Alerts on WER EventID 1001 crashes where MsMpEng.exe and mpengine.dll appear in the event data.

FreeReviewedSigma · High · v2
Product
windows
Service
application
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-05-09
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Error Reporting events indicating a crash involving MsMpEng.exe and mpengine.dll. Attackers may leverage stability issues in security components to impair defenses, so unexpected crashes are operationally important to investigate. The detection relies on Windows Application logs (Provider_Name: Windows Error Reporting) with EventID 1001 and event data containing both process and module names.

Related detections9 linkedT1211 — drag to rearrange
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
Suspicious Staged Payload Execution from User Downloads or Pictures Folder
Malicious Vulnerable Driver Deployment for EDR Termination via file_event
Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Pivot detection · T1211 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.