Event ID 3082 — Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system.
Description
Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system. However, due to code integrity auditing policy, the image was allowed to load.
Message #
Fields #
| Name | Description |
|---|---|
FileNameLength UInt16 | — |
FileNameBuffer UnicodeString | — |
Detection Rules #
View all rules referencing this event →
Sigma # view in reference
- CodeIntegrity - Unmet WHQL Requirements For Loaded Kernel Module source high: Detects loaded kernel modules that did not meet the WHQL signing requirements.↳ also matches:Event ID 3083: Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system.