Microsoft-Windows-CodeIntegrity › Event 3023

Event ID 3023 — The driver FileNameBuffer is blocked from loading as the driver has been revoked by Microsoft.

Provider
Microsoft-Windows-CodeIntegrity
Channel
Operational
Collection Priority
Recommended (NSA, others)
Task
CreateSection
Opcode
RevokedDriverNotLoaded

Description

The driver FileNameBuffer is blocked from loading as the driver has been revoked by Microsoft.

Message #

The driver %2 is blocked from loading as the driver has been revoked by Microsoft.

Fields #

NameDescription
FileNameLength UInt16
FileNameBuffer UnicodeString
SecureRequired HexInt32
RequestedSigningLevel UInt8
ProcessNameLength UInt16
ProcessNameBuffer UnicodeString

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

References #