Windows: User Profiles Service EventID 1511 indicating potential CVE-2022-21919 or CVE-2021-34484 LPE

Alerts on User Profiles Service Event ID 1511, a possible signal of LPE exploitation attempts associated with CVE-2022-21919 or CVE-2021-34484.

FreeReviewedSigma · Low · v5
Product
windows
Service
application
Author
Cybex (SigmaHQ), DRL 1.1
Published
2022-08-16
Updated
2026-07-31

What it detects

This rule flags Windows events from the Microsoft-Windows-User Profiles Service with EventID 1511, which can correspond to attempts to exploit CVE-2022-21919 or CVE-2021-34484 for local privilege escalation via the User Profile Service. Such exploitation matters because it may enable escalation from a lower-privileged context. It relies on Windows application/service telemetry capturing Provider_Name and EventID for the User Profiles Service, with the accompanying guidance noting additional related events (EventID 1515) and possible creation of \Users\TEMP during exploitation.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.