Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)

Flags Windows SRP enforcement events where attempts to access applications are restricted by administrator policy.

FreeReviewedSigma · High · v2
Product
windows
Service
application
Author
frack113 (SigmaHQ), DRL 1.1
Published
2023-01-12
Updated
2026-07-31

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows events from the Software Restriction Policies provider indicating that access to a specified application was blocked by administrator-configured SRP rules. Such blocks matter because attackers often rely on executing restricted binaries or from specific paths/publishers to achieve execution or lateral movement. The detection relies on Windows application telemetry from the Microsoft-Windows-SoftwareRestrictionPolicies provider and the specified Event IDs.

Related detections3 linkedT1072 — drag to rearrange
Windows PDQ Deploy Console Execution
Radmin Viewer Utility Execution on Windows (Process Creation)
Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Pivot detection · T1072 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.