Detection rules › Sigma

CodeIntegrity - Revoked Image Loaded

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects image load events with revoked certificates by code integrity.

Event coverage

ProviderEvent IDTitle
CodeIntegrity3032Code Integrity determined a revoked image FileNameBuffer is loaded into the system.
CodeIntegrity3035Code Integrity determined a revoked image FileNameBuffer is loaded into the system.

Stages and Predicates

Stage 1: selection