Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)
Alerts on Code Integrity file-load attempts failing signing level requirements, based on Event ID 3033/3034 in Windows Code Integrity logs.
- Product
- windows
- Service
- codeintegrity-operational
- Author
- Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-01-20
- Updated
- 2026-07-31
What it detects
This rule flags Windows Code Integrity events where a process attempted to load an image that did not satisfy the configured signing level requirements. Such failures can indicate revoked signatures, expired signing EKUs, or other code integrity policy mismatches that may prevent or restrict execution. The detection relies on Code Integrity Operational log telemetry for Event IDs 3033 and 3034, which include the loading process, target image, and the requested signing policy.
Reporting behind it
- twitter.comhttps://twitter.com/SBousseaden/status/1483810148602814466
- github.comhttps://github.com/MicrosoftDocs/windows-itpro-docs/blob/40fe118976734578f83e5e839b9c63ae7a4af82d/windows/security/threat-protection/windows-defender-application-control/event-id-explanations.md#windows-codeintegrity-operational-log
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/operations/event-tag-explanations
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/operations/event-id-explanations
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)"
id: 8970180f-6fee-4ef6-8482-3b5702903804
status: experimental
description: This rule flags Windows Code Integrity events where a process attempted to load an image that did not satisfy the configured signing level requirements. Such failures can indicate revoked signatures, expired signing EKUs, or other code integrity policy mismatches that may prevent or restrict execution. The detection relies on Code Integrity Operational log telemetry for Event IDs 3033 and 3034, which include the loading process, target image, and the requested signing policy.
references:
- https://twitter.com/SBousseaden/status/1483810148602814466
- https://github.com/MicrosoftDocs/windows-itpro-docs/blob/40fe118976734578f83e5e839b9c63ae7a4af82d/windows/security/threat-protection/windows-defender-application-control/event-id-explanations.md#windows-codeintegrity-operational-log
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/operations/event-tag-explanations
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/operations/event-id-explanations
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-01-20
modified: 2025-02-28
tags:
- attack.execution
logsource:
product: windows
service: codeintegrity-operational
detection:
selection:
EventID:
- 3033
- 3034
filter_optional_dtrace:
FileNameBuffer|endswith: \Program Files\DTrace\dtrace.dll
ProcessNameBuffer|endswith: \Windows\System32\svchost.exe
RequestedPolicy: 12
filter_optional_av_generic:
FileNameBuffer|contains: \Windows\System32\DriverStore\FileRepository\
FileNameBuffer|endswith: \igd10iumd64.dll
RequestedPolicy: 7
filter_optional_electron_based_app:
FileNameBuffer|endswith: \Windows\System32\nvspcap64.dll
ProcessNameBuffer|endswith:
- \AppData\Local\Keybase\Gui\Keybase.exe
- \Microsoft\Teams\stage\Teams.exe
RequestedPolicy: 8
filter_optional_bonjour:
FileNameBuffer|endswith: \Program Files\Bonjour\mdnsNSP.dll
ProcessNameBuffer|endswith:
- \Windows\System32\svchost.exe
- \Windows\System32\SIHClient.exe
RequestedPolicy:
- 8
- 12
filter_optional_msoffice_1:
FileNameBuffer|contains: \Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE
FileNameBuffer|endswith: \MSOXMLMF.DLL
RequestedPolicy: 7
filter_optional_msoffice_2:
ProcessNameBuffer|contains: \Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office
FileNameBuffer|contains: \Windows\System32\
RequestedPolicy: 8
filter_optional_slack:
FileNameBuffer|endswith: \Windows\System32\nvspcap64.dll
ProcessNameBuffer|contains: \AppData\Local\slack\app-
ProcessNameBuffer|endswith: \slack.exe
RequestedPolicy: 8
filter_optional_firefox:
FileNameBuffer|endswith:
- \Mozilla Firefox\mozavcodec.dll
- \Mozilla Firefox\mozavutil.dll
ProcessNameBuffer|endswith: \Mozilla Firefox\firefox.exe
RequestedPolicy: 8
filter_optional_avast:
FileNameBuffer|endswith:
- \Program Files\Avast Software\Avast\aswAMSI.dll
- \Program Files (x86)\Avast Software\Avast\aswAMSI.dll
RequestedPolicy:
- 8
- 12
filter_main_gac:
FileNameBuffer|contains: \Windows\assembly\GAC\
ProcessNameBuffer|endswith: \mscorsvw.exe
ProcessNameBuffer|contains: \Windows\Microsoft.NET\
RequestedPolicy: 8
filter_optional_google_drive:
FileNameBuffer|contains: \Program Files\Google\Drive File Stream\
FileNameBuffer|endswith: \crashpad_handler.exe
ProcessNameBuffer|endswith: \Windows\ImmersiveControlPanel\SystemSettings.exe
RequestedPolicy: 8
filter_optional_trend_micro:
FileNameBuffer|endswith: \Trend Micro\Client Server Security Agent\perficrcperfmonmgr.dll
RequestedPolicy: 8
filter_optional_mdns_responder:
FileNameBuffer|endswith: "\\Program Files\\National Instruments\\Shared\\mDNS Responder\\nimdnsNSP.dll "
filter_optional_mcafee:
FileNameBuffer|endswith:
- \Program Files\McAfee\Endpoint Security\Threat Prevention\MfeAmsiProvider.dll
- \Program Files\McAfee\MfeAV\AMSIExt.dll
filter_optional_eset:
FileNameBuffer|endswith: \Program Files\ESET\ESET Security\eamsi.dll
filter_optional_comodo:
FileNameBuffer|endswith: \Program Files\comodo\comodo internet security\amsiprovider_x64.dll
filter_optional_sentinel_one:
- FileNameBuffer|contains: \Program Files\SentinelOne\Sentinel Agent
- ProcessNameBuffer|contains: \Program Files\SentinelOne\Sentinel Agent
filter_optional_national_instruments:
FileNameBuffer|contains: \National Instruments\Shared\mDNS Responder\
filter_optional_kaspersky:
- ProcessNameBuffer|contains|all:
- \Kaspersky Lab\
- \avp.exe
- FileNameBuffer|contains|all:
- \Kaspersky Lab\
- \antimalware_provider.dll
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Antivirus and other third party products are known to trigger this rule quite a lot. Initial filters and tuning is required before using this rule.
level: low
license: DRL-1.1
related:
- id: f8931561-97f5-4c46-907f-0a4a592e47a7
type: derived