Windows System Logs: Windows Update Client errors (connection, install, uninstall, revert, commit)

Alerts on Windows Update Client errors in System logs, including connection, install, uninstall, revert, and commit failures.

FreeReviewedSigma · Informational · v2
Product
windows
Service
system
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-04
Updated
2026-07-31

ATT&CK techniques

Resource Dev
  1. Recon

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Update Client events from the Microsoft-Windows-WindowsUpdateClient provider indicating failures to connect to the updates service or failures during install, uninstall, revert, or commit operations. Such errors matter because attackers and administrators alike may cause or mask update disruptions, preventing patches from being applied on schedule. It relies on system telemetry capturing Windows Update Client event records with the specified event IDs.

Related detections3 linkedT1584 — drag to rearrange
Proxy WebDAV MiniRedir Drives Execution from External Shares
Windows WebDAV Temporary File Creation with Suspicious Extensions
Linux Auditd: Program Executions from Suspicious Web and Data Directories
Windows System Logs: Windows Update Client errors (connection, install, uninstall, revert, commit)
Pivot detection · T1584 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.