Windows WER BugCheck Crash Dump Reporting via Event ID 1001

Flags Windows WER SystemErrorReporting Event ID 1001 entries indicating a crash with bugcheck and dump/report details.

FreeReviewedSigma · Medium · v2
Product
windows
Service
system
Author
Jason Mull (SigmaHQ), DRL 1.1
Published
2025-05-12
Updated
2026-07-31

ATT&CK techniques

Cred Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows SystemErrorReporting events from the WER provider that indicate a BugCheck crash and a subsequent system reboot. Attackers may trigger or leverage crashes to disrupt systems or stage activity, so capturing these crash indicators helps correlate instability with other suspicious behavior. The detection relies on Windows System event telemetry from the Microsoft-Windows-WER-SystemErrorReporting provider, matching Event ID 1001 and extracting fields such as the bugcheck code, dump file path, and report ID.

Related detections9 linkedT1003.002 — drag to rearrange
Suspicious Archiving of Registry Hives via WinRAR (UAT-8099)
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Malicious Registry Hive Dump of SAM or SYSTEM via Reg Save (via process_creation)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Malicious Credential Hive Copy from Volume Shadow Copy
Malicious Secretdump Password Dumping via SMB Admin Share (via security)
Malicious Registry Hive Dump of SAM and SYSTEM via Reg Save (via process_creation)
Suspicious SAM Registry Hive Dump to Windows Temp by BianLian
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Windows WER BugCheck Crash Dump Reporting via Event ID 1001
Pivot detection · T1003.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.