RPC Firewall: Remote MS-EFSR encryption interface calls (EventID 3)

Alerts on RPC Firewall events targeting MS-EFSR interface UUIDs associated with remote encrypting file system abuse.

FreeReviewedSigma · High · v5
Product
rpc_firewall
Category
application
Author
Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-31

What it detects

This rule flags RPC Firewall application events where remote calls target the MS-EFSR interface UUIDs. Such remote encryption service abuse can support attacker staging or lateral movement by interacting with file encryption mechanisms over RPC. It relies on RPCFW EventLog entries with EventID 3 and matching interface UUIDs.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.