diff --git a/evtx/Maps/Application_Microsoft-Windows-Winsrv_10001.map b/evtx/Maps/Application_Microsoft-Windows-Winsrv_10001.map new file mode 100644 index 00000000..5c4a9039 --- /dev/null +++ b/evtx/Maps/Application_Microsoft-Windows-Winsrv_10001.map @@ -0,0 +1,43 @@ +Author: Tony Knutson +Description: Application is stopping shutdown operation +EventId: 10001 +Channel: "Application" +Provider: "Microsoft-Windows-Winsrv" +Maps: + - + Property: ExecutableInfo + PropertyValue: "%AppName%" + Values: + - + Name: AppName + Value: "/Event/UserData/VetoAppEvent/AppName" + +# Documentation: +# http://deusexmachina.uk/evdoco/event.php?event=1025 +# A shutdown or hibernation has been requested, but this application, upon receiving the WM_QUERYENDSESSION message, has responded with a zero - meaning no, don't shut me down! I'm not done here yet!. +# +# Example Event Data: +# - +# - +# +# 10001 +# 0 +# 4 +# 0 +# 0 +# 0x8000000000000000 +# +# 1648636 +# +# +# Application +# COMPUTERNAME +# +# +# - +# +# NAME OF PROGRAM +# 0 +# +# +#