Detection rules › Sigma

CodeIntegrity - Blocked Driver Load With Revoked Certificate

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects blocked load attempts of revoked drivers

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1543 Create or Modify System Process
Privilege EscalationT1543 Create or Modify System Process

Event coverage

ProviderEvent IDTitle
CodeIntegrity3023The driver FileNameBuffer is blocked from loading as the driver has been revoked by Microsoft.

Stages and Predicates

Stage 1: selection