eventcreate.exe

  • File Path: C:\WINDOWS\system32\eventcreate.exe
  • Description: Event Create - Creates a custom event in an event log

Hashes

Type Hash
MD5 EB23D3CF2B2DA9A91F5A8E5F968C08BF
SHA1 93C6F1A65CA550AF93AB21C4B5437616487E346B
SHA256 4B9E6664D87ECE17DE79AF7655A819F2DDB31987D22375CB13C7853C007AF18A
SHA384 85ABA52DD9199976CA8D2BF0A3F082B1BD1924726E9D5DF58E652AE930D187E56B4CDAA918BA3274AAF4BDFD37AF3835
SHA512 AD425E461FFAA492CE5E46E4E6C9AAB67DAEC243154E4D8A9586E2C08720464A7BDADB41C4358D7944A7751FD542BF959FC7B22E7D8AC5B88768DF226CAA209D
SSDEEP 768:cURbHomXdIS0pd6dOBZdAjWb7s/v4lXYQQy1Vf7lCqoaCNAQ:ZRk+dydOOhEWU/EYQF7lCLaUAQ
IMP C2409212CE77AEE27A3AC6C3A1C2EC8C
PESHA1 C2F91C2F0F7BF8A292994DE606BA13D9E70D95A2
PE256 AEEEC83418B1F8C1993D9C4A613D4E294644D5272D5FB7471F509A4B97F6E454

Runtime Data

Usage (stdout):


EVENTCREATE [/S system [/U username [/P [password]]]] /ID eventid
            [/L logname] [/SO srcname] /T type /D description

Description:
    This command line tool enables an administrator to create
    a custom event ID and message in a specified event log.

Parameter List:
    /S    system           Specifies the remote system to connect to.

    /U    [domain\]user    Specifies the user context under which
                           the command should execute.

    /P    [password]       Specifies the password for the given
                           user context. Prompts for input if omitted.

    /L    logname          Specifies the event log to create
                           an event in.

    /T    type             Specifies the type of event to create.
                           Valid types: SUCCESS, ERROR, WARNING, INFORMATION.

    /SO   source           Specifies the source to use for the
                           event (if not specified, source will default
                           to 'eventcreate'). A valid source can be any
                           string and should represent the application
                           or component that is generating the event.

    /ID   id               Specifies the event ID for the event. A
                           valid custom message ID is in the range
                           of 1 - 1000.

    /D    description      Specifies the description text for the new event.

    /?                     Displays this help message.


Examples:
    EVENTCREATE /T ERROR /ID 1000
        /L APPLICATION /D "My custom error event for the application log"

    EVENTCREATE /T ERROR /ID 999 /L APPLICATION
        /SO WinWord /D "Winword event 999 happened due to low diskspace"

    EVENTCREATE /S system /T ERROR /ID 100
        /L APPLICATION /D "Custom job failed to install"

    EVENTCREATE /S system /U user /P password /ID 1 /T ERROR
        /L APPLICATION /D "User access failed due to invalid user credentials"

Usage (stderr):

ERROR: Invalid argument/option - '--help'.
Type "EVENTCREATE /?" for usage.

Loaded Modules:

Path
C:\WINDOWS\system32\eventcreate.exe
C:\WINDOWS\System32\KERNEL32.DLL
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: evcreate.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/4b9e6664d87ece17de79af7655a819f2ddb31987d22375cb13c7853c007af18a/detection

Additional Info*

*The information below is copied from MicrosoftDocs, which is maintained by Microsoft. Available under CC BY 4.0 license.


eventcreate

Enables an administrator to create a custom event in a specified event log.

[!IMPORTANT] Custom events can’t be written to the security log.

Syntax

eventcreate [/s <computer> [/u <domain\user> [/p <password>]] {[/l {APPLICATION|SYSTEM}]|[/so <srcname>]} /t {ERROR|WARNING|INFORMATION|SUCCESSAUDIT|FAILUREAUDIT} /id <eventID> /d <description>

Parameters

Parameter Description
/s <computer> Specifies the name or IP address of a remote computer (do not use backslashes). The default is the local computer.
/u <domain\user> Runs the command with the account permissions of the user specified by <user> or <domain\user>. The default is the permissions of the current logged on user on the computer issuing the command.
/p <password> Specifies the password of the user account that is specified in the /u parameter.
/l {APPLICATION | SYSTEM} Specifies the name of the event log where the event will be created. The valid log names are APPLICATION or SYSTEM.
/so <srcname> Specifies the source to use for the event. A valid source can be any string and should represent the application or component that is generating the event.
/t {ERROR | WARNING | INFORMATION | SUCCESSAUDIT | FAILUREAUDIT} Specifies the type of event to create. The valid types are ERROR, WARNING, INFORMATION, SUCCESSAUDIT, and FAILUREAUDIT.
/id <eventID> Specifies the event ID for the event. A valid ID is any number from 1 to 1000.
/d <description> Specifies the description to use for the newly created event.
/? Displays help at the command prompt.

Examples

The following examples show how you can use the eventcreate command:

eventcreate /t ERROR /id 100 /l application /d "Create event in application log"
eventcreate /t INFORMATION /id 1000 /d "Create event in WinMgmt source"
eventcreate /t ERROR /id 201 /so winword /l application /d "New src Winword in application log"
eventcreate /s server /t ERROR /id 100 /l application /d "Remote machine without user credentials"
eventcreate /s server /u user /p password /id 100 /t ERROR /l application /d "Remote machine with user credentials"
eventcreate /s server1 /s server2 /u user /p password /id 100 /t ERROR /d "Creating events on Multiple remote machines"
eventcreate /s server /u user /id 100 /t WARNING /d "Remote machine with partial user credentials"

Additional References


MIT License. Copyright (c) 2020-2021 Strontic.