Windows Code Integrity: Kernel Module Loaded Without WHQL Requirements (Event 3082/3083)

Alerts when Code Integrity logs show loaded kernel modules failing WHQL compliance (Event 3082/3083), excluding selected VMware drivers.

FreeReviewedSigma · High · v2
Product
windows
Service
codeintegrity-operational
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-06-06
Updated
2026-07-31

What it detects

This rule identifies kernel modules that Code Integrity determines did not meet WHQL signing requirements after being loaded into the system. Attackers may try to introduce or load non-compliant kernel components to gain privileged execution, so flagging these events can highlight trust boundary violations. It relies on Windows Code Integrity operational telemetry for Event ID 3082 and 3083 and applies an exclusion for specific VMware driver filenames.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.