RPC Firewall: Remote MS-EFSR encryption interface calls (EventID 3)
Alerts on RPC Firewall events targeting MS-EFSR interface UUIDs associated with remote encrypting file system abuse.
FreeReviewedSigma · High · v5
- Product
- rpc_firewall
- Category
- application
- Author
- Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
- Published
- 2022-01-01
- Updated
- 2026-07-31
What it detects
This rule flags RPC Firewall application events where remote calls target the MS-EFSR interface UUIDs. Such remote encryption service abuse can support attacker staging or lateral movement by interacting with file encryption mechanisms over RPC. It relies on RPCFW EventLog entries with EventID 3 and matching interface UUIDs.
Reporting behind it
- msrc.microsoft.comhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942
- github.comhttps://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-EFSR.md
- github.comhttps://github.com/zeronetworks/rpcfirewall
- zeronetworks.comhttps://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_efs_abuse.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
rpc-firewall-detection-for-remote-ms-efsr-encrypting-file-system-abuse-5f92fff9
title: "RPC Firewall: Remote MS-EFSR encryption interface calls (EventID 3)"
id: 32f246d3-582e-4ef7-8d52-a172f3dc9104
status: test
description: This rule flags RPC Firewall application events where remote calls target the MS-EFSR interface UUIDs. Such remote encryption service abuse can support attacker staging or lateral movement by interacting with file encryption mechanisms over RPC. It relies on RPCFW EventLog entries with EventID 3 and matching interface UUIDs.
references:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942
- https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-EFSR.md
- https://github.com/zeronetworks/rpcfirewall
- https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_efs_abuse.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
- attack.lateral-movement
logsource:
product: rpc_firewall
category: application
definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:df1941c5-fe89-4e79-bf10-463657acf44d or c681d488-d850-11d0-8c52-00c04fd90f7e'
detection:
selection:
EventLog: RPCFW
EventID: 3
InterfaceUuid:
- df1941c5-fe89-4e79-bf10-463657acf44d
- c681d488-d850-11d0-8c52-00c04fd90f7e
condition: selection
falsepositives:
- Legitimate usage of remote file encryption
level: high
license: DRL-1.1
related:
- id: 5f92fff9-82e2-48eb-8fc1-8b133556a551
type: derived