Remote Event Log Recon via RPCFW EVEN/EVEN6 EventID 3 (RPC interface UUIDs)

Flags RPC Firewall EventID 3 remote calls querying Windows Event Log data over EVEN/EVEN6 interfaces.

FreeReviewedSigma · High · v5
Product
rpc_firewall
Category
application
Author
Sagie Dulce, Dekel Paz (SigmaHQ), DRL 1.1
Published
2022-01-01
Updated
2026-07-31

What it detects

This rule flags RPC firewall events indicating remote requests for event log information using EVEN or EVEN6, identified by EventID 3. Such recon can help an attacker enumerate or validate access to Windows event logging before further actions. Detection relies on RPCFW application telemetry that includes EventLog, EventID, and the specific InterfaceUuid values involved in the remote call.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.