Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
FreeUnreviewedSigmahighv1
windows-code-integrity-blocked-disallowed-file-for-protected-processes-event-id--5daf11c3
title: Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
id: 2042d844-8800-4ddc-9122-b3ed111e3da8
status: test
description: This rule flags Windows Code Integrity events where a file was blocked because it is disallowed for protected processes. Blocking disallowed binaries is a strong control for preventing unauthorized execution, and attackers may attempt to run or load such files to escalate privileges or bypass process protections. It relies on Code Integrity operational telemetry reporting Event ID 3104 that indicates the protected-process disallow decision.
references:
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/operations/event-id-explanations
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/operations/event-tag-explanations
- Internal Research
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/code_integrity/win_codeintegrity_blocked_protected_process_file.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-06
tags:
- attack.privilege-escalation
logsource:
product: windows
service: codeintegrity-operational
detection:
selection:
EventID: 3104
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: 5daf11c3-022b-4969-adb9-365e6c078c7c
type: derived
What it detects
This rule flags Windows Code Integrity events where a file was blocked because it is disallowed for protected processes. Blocking disallowed binaries is a strong control for preventing unauthorized execution, and attackers may attempt to run or load such files to escalate privileges or bypass process protections. It relies on Code Integrity operational telemetry reporting Event ID 3104 that indicates the protected-process disallow decision.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.