Windows Security Event 6423: Device Installation Blocked by Policy

Alerts when Windows blocks a device installation due to enforced system policy (Event ID 6423).

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-10-14
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security log events indicating that a device installation was blocked because it is forbidden by system policy. Attackers may attempt to introduce unauthorized peripherals or drivers during initial access, and policy enforcement that blocks these actions is important for containment. Detection relies on Security audit telemetry specifically reporting EventID 6423.

Related detections2 linkedT1200 — drag to rearrange
Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Windows Security Event 6423: Device Installation Blocked by Policy
Pivot detection · T1200 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.