Detection rules › Sigma

CodeIntegrity - Blocked Image Load With Revoked Certificate

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects blocked image load events with revoked certificates by code integrity.

Event coverage

ProviderEvent IDTitle
CodeIntegrity3036Windows is unable to verify the integrity of the file FileNameBuffer because the signing certificate has been revoked.

Stages and Predicates

Stage 1: selection