Detection rules › Sigma

CodeIntegrity - Unsigned Image Loaded

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects loaded unsigned image on the system

Event coverage

ProviderEvent IDTitle
CodeIntegrity3037Code Integrity determined an unsigned image FileNameBuffer is loaded into the system.

Stages and Predicates

Stage 1: selection