Windows Application: MSMQ Corrupted Packet (Event ID 2027, Level 2)

Alerts on MSMQ Event ID 2027 (level 2) indicating corrupted packets received by the service.

FreeReviewedSigma · High · v5
Product
windows
Service
application
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-21
Updated
2026-07-31

What it detects

This rule flags Windows application events indicating that MSMQ encountered a corrupted packet, specifically Event ID 2027 with severity level 2 and Provider_Name set to MSMQ. Such errors matter because malformed or corrupted traffic may indicate attempted exploitation or disruptive probing against the MSMQ service. The detection relies on Windows application telemetry carrying the MSMQ provider and the event’s Event ID and level.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.