Windows Code Integrity blocked image/driver loads due to signature level or policy violations

Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.

FreeReviewedSigma · High · v2
Product
windows
Service
codeintegrity-operational
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-11-10
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Code Integrity Operational events where a process attempted to load an image or driver that failed signing level requirements or violated the configured code integrity policy. Attackers can use unsigned or improperly signed modules to bypass trust boundaries, making these blocked loads a valuable indicator of attempted persistence or privilege escalation. The detection relies on Windows Code Integrity Operational telemetry, specifically events indicating the load was blocked for signing level and/or policy reasons.

Related detections9 linkedT1543 — drag to rearrange
Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path
Suspicious SonicWall SMA init.d Persistence Launching deploy_new.py
Malicious Linux XorDDoS gcc.pid Device Marker File via file_event
Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Windows PUA System Informer Driver Load via SystemInformer.sys
System Informer Execution on Windows Process Creation
Windows Driver Load: Process Hacker (processhacker.sys) Presence
Windows Process Hacker Execution Identified by Image Metadata and Hashes
Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Pivot detection · T1543 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.