Windows Code Integrity Unsigned Kernel Module Loaded (Event ID 3001)

Alerts on Windows Code Integrity reporting an unsigned kernel module load via Event ID 3001.

FreeReviewedSigma · High · v2
Product
windows
Service
codeintegrity-operational
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-06-06
Updated
2026-07-31

What it detects

This rule flags Windows events indicating Code Integrity has loaded an unsigned kernel module into the system. Attackers may abuse unsigned or improperly signed kernel modules to bypass trust controls and gain elevated capabilities at the kernel level. The detection relies on Code Integrity Operational telemetry reporting Event ID 3001, including the module information provided in the event.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.