kevmap

Log sources › WinEventLog:Microsoft-Windows-CodeIntegrity/Operational

WinEventLog:Microsoft-Windows-CodeIntegrity/Operational

Inverted view: what can be detected if this is the log you have. Windows

7
channels
7
analytics
7
techniques
3
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Code integrity violations in boot-start drivers or firmware DC0059 File Metadata AN1035 1
CodeIntegrity reports 'Invalid image hash' or 'Unsigned image' for new/updated binaries DC0059 File Metadata AN1480 1
CodeIntegrity/WDAC events indicating unsigned/invalid DLL loads DC0034 Process Metadata AN0052 1
Invalid/Unsigned image when developer tool launches newly installed binaries DC0059 File Metadata AN0021 1
Unsigned or invalid image for newly installed/updated binaries DC0059 File Metadata AN0862 1
Unsigned or untrusted modules loaded during JamPlus.exe runtime DC0034 Process Metadata AN1610 1
Unsigned/invalid signature modules or images loaded by msbuild.exe or its children DC0034 Process Metadata AN1535 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1127.001 MSBuildstealth, execution10
T1127.003 JamPlusstealth, execution00
T1129 Shared Modulesexecution20
T1195 Supply Chain Compromiseinitial access11
T1195.001 Compromise Software Dependencies and Development Toolsinitial access20
T1195.002 Compromise Software Supply Chaininitial access172
T1195.003 Compromise Hardware Supply Chaininitial access00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1195.002 Mapped
CVE-2024-49035Microsoft Partner Center T1195 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1195.002 Mapped