Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)

Alerts on Code Integrity file-load attempts failing signing level requirements, based on Event ID 3033/3034 in Windows Code Integrity logs.

FreeReviewedSigma · Low · v2
Product
windows
Service
codeintegrity-operational
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-01-20
Updated
2026-07-31

What it detects

This rule flags Windows Code Integrity events where a process attempted to load an image that did not satisfy the configured signing level requirements. Such failures can indicate revoked signatures, expired signing EKUs, or other code integrity policy mismatches that may prevent or restrict execution. The detection relies on Code Integrity Operational log telemetry for Event IDs 3033 and 3034, which include the loading process, target image, and the requested signing policy.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.