RPC Firewall: Remote MS-EFSR encryption interface calls (EventID 3)

Alerts on RPC Firewall events targeting MS-EFSR interface UUIDs associated with remote encrypting file system abuse.

FreeReviewedSigma · High · v5
Product
rpc_firewall
Category
application
Author
Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-31
title: "RPC Firewall: Remote MS-EFSR encryption interface calls (EventID 3)"
id: 32f246d3-582e-4ef7-8d52-a172f3dc9104
status: test
description: This rule flags RPC Firewall application events where remote calls target the MS-EFSR interface UUIDs. Such remote encryption service abuse can support attacker staging or lateral movement by interacting with file encryption mechanisms over RPC. It relies on RPCFW EventLog entries with EventID 3 and matching interface UUIDs.
references:
  - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36942
  - https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-EFSR.md
  - https://github.com/zeronetworks/rpcfirewall
  - https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/rpc_firewall/rpc_firewall_efs_abuse.yml
author: Sagie Dulce, Dekel Paz, Huntrule Team
date: 2022-01-01
tags:
  - attack.lateral-movement
logsource:
  product: rpc_firewall
  category: application
  definition: 'Requirements: install and apply the RPC Firewall to all processes with "audit:true action:block uuid:df1941c5-fe89-4e79-bf10-463657acf44d or c681d488-d850-11d0-8c52-00c04fd90f7e'
detection:
  selection:
    EventLog: RPCFW
    EventID: 3
    InterfaceUuid:
      - df1941c5-fe89-4e79-bf10-463657acf44d
      - c681d488-d850-11d0-8c52-00c04fd90f7e
  condition: selection
falsepositives:
  - Legitimate usage of remote file encryption
level: high
license: DRL-1.1
related:
  - id: 5f92fff9-82e2-48eb-8fc1-8b133556a551
    type: derived