Detection rules › Sigma
CodeIntegrity - Disallowed File For Protected Processes Has Been Blocked
Detects block events for files that are disallowed by code integrity for protected processes
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| CodeIntegrity | 3104 | Windows blocked file FileNameBuffer which has been disallowed for protected processes. |