Log sources › WinEventLog:Microsoft-Windows-CodeIntegrity/Operational
WinEventLog:Microsoft-Windows-CodeIntegrity/Operational
Inverted view: what can be detected if this is the log you have. Windows
7
channels
7
analytics
7
techniques
3
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Code integrity violations in boot-start drivers or firmware |
DC0059 File Metadata | AN1035 | 1 |
CodeIntegrity reports 'Invalid image hash' or 'Unsigned image' for new/updated binaries |
DC0059 File Metadata | AN1480 | 1 |
CodeIntegrity/WDAC events indicating unsigned/invalid DLL loads |
DC0034 Process Metadata | AN0052 | 1 |
Invalid/Unsigned image when developer tool launches newly installed binaries |
DC0059 File Metadata | AN0021 | 1 |
Unsigned or invalid image for newly installed/updated binaries |
DC0059 File Metadata | AN0862 | 1 |
Unsigned or untrusted modules loaded during JamPlus.exe runtime |
DC0034 Process Metadata | AN1610 | 1 |
Unsigned/invalid signature modules or images loaded by msbuild.exe or its children |
DC0034 Process Metadata | AN1535 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1127.001 MSBuild | stealth, execution | 1 | 0 |
| T1127.003 JamPlus | stealth, execution | 0 | 0 |
| T1129 Shared Modules | execution | 2 | 0 |
| T1195 Supply Chain Compromise | initial access | 1 | 1 |
| T1195.001 Compromise Software Dependencies and Development Tools | initial access | 2 | 0 |
| T1195.002 Compromise Software Supply Chain | initial access | 17 | 2 |
| T1195.003 Compromise Hardware Supply Chain | initial access | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | T1195.002 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1195 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1195.002 | Mapped |