Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll

Alerts on Windows Application Error EventID 1000 indicating a crash involving MsMpEng.exe and mpengine.dll.

FreeReviewedSigma · High · v2
Product
windows
Service
application
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-05-09
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Application Error events where the process MsMpEng.exe is reported crashing and the event data includes mpengine.dll. Such crashes can be leveraged to impair or disrupt Microsoft Malware Protection Engine functionality during an attack or after malicious activity. The detection relies on Windows Application log telemetry, specifically EventID 1000 with provider name Application Error and matching crash-related strings in the event data.

Related detections9 linkedT1211 — drag to rearrange
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Suspicious Vulnerable Driver Load for BYOVD Abuse by DragonForce Ransomware (via driver_load)
Suspicious Staged Payload Execution from User Downloads or Pictures Folder
Malicious Vulnerable Driver Deployment for EDR Termination via file_event
Possible PAN-OS Auth Bypass via Double-Encoded Path Traversal to ztp_gate (CVE-2025-0108)
Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Pivot detection · T1211 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.