Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)

Alerts on Windows Audit-CVE EventID 1 entries from Microsoft-Windows-Audit-CVE provider indicating CveEventWrite activity.

FreeReviewedSigma · Critical · v2
Product
windows
Service
application
Author
Florian Roth (Nextron Systems), Zach Mathis (SigmaHQ), DRL 1.1
Published
2020-01-15
Updated
2026-07-31

ATT&CK techniques

Execution → Impact

What it detects

This rule flags Windows application log events from the Microsoft-Windows-Audit-CVE provider, matching Event ID 1, that are generated when a user-mode application calls the CveEventWrite API. Attackers may use these events to surface or signal exploitation attempts tied to specific CVE activity, making this useful for spotting anomalous vulnerability-reporting behavior. Telemetry relies on Windows Application logs capturing the Provider_Name and EventID values for the Audit-CVE event stream.

Related detections9 linkedT1068 — drag to rearrange
Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Suspicious Dell ControlVault DLL Load by Unexpected Process (ReVault)
Suspicious Vulnerable ASUS AsIO3.sys Driver Load
Malicious Bring-Your-Own-Vulnerable-Driver Load By BlackByte
Windows spoolsv.exe Child Process Execution Indicators
Malicious JuicyPotato Privilege Escalation Execution (UAT-7237)
Malicious Known Vulnerable Driver Load for BYOVD Attack
Malicious Qilin EDR Killer BYOVD Driver Load
Malicious Looney Tunables Privilege Escalation Exploit by Kinsing (via process_creation)
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Pivot detection · T1068 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.