Windows Event ID 1001 — Windows Error Reporting — Application or System Crash
Logged by Windows Error Reporting when an application crashes or a BSOD occurs, including the fault module and exception code.
Why It Matters
Provides the crash analysis that Event ID 41 lacks. The faulting module name often identifies the driver or application causing instability.
Key Fields
Investigation Tips
- 1.lsass.exe crashes can be caused by credential dumping tools — investigate the surrounding timeline.
- 2.Third-party driver paths in Faulting Module Name point to the vendor responsible for the instability.
- 3.Recurring crashes with the same module + exception code confirm a specific root cause.
Seeing Event ID 1001 in your own logs? Upload an .evtx file — EventPeeker flags windows error reporting — application or system crash automatically, maps it to MITRE ATT&CK, and writes the triage report. No account, files auto-deleted.
Analyze my logs →Related Event IDs
Have Event ID 1001 open in Event Viewer?
In Event Viewer: right-click the event → Copy → Copy Details as XML, then paste it below. Parsing happens entirely in your browser — the event itself is never uploaded or stored, and it is excluded from session recording. We log only the numeric Event ID.
See Event ID 1001 in your logs
Upload a Windows Event Log (.evtx) file — EventPeeker automatically detects windows error reporting — application or system crash patterns, maps findings to MITRE ATT&CK, and generates an AI triage report.
Analyze EVTX Logs Free →