1200KM / sigma-rule
Audit CVE Event — Sigma Rule
Sigma rule 48d91a3a-2363-43ba-a456-ca71ac3da5c2. Audit CVE Event — Sigma Rule. Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
Rule metadata and linked tags
Author: Florian Roth (Nextron Systems), Zach Mathis. Source status: test; severity: critical. Source dates: 2020-01-15 / 2022-10-22.
{
"product": "windows",
"service": "application"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 25d26904f1984a071814cdbf18eeb06658c086ceaf37ae059138138dc6c15e4d
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Audit CVE Event
id: 48d91a3a-2363-43ba-a456-ca71ac3da5c2
status: test
description: |
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited.
MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability.
Unfortunately, that is about the only instance of CVEs being written to this log.
references:
- https://twitter.com/VM_vivisector/status/1217190929330655232
- https://twitter.com/DidierStevens/status/1217533958096924676
- https://twitter.com/FlemmingRiis/status/1217147415482060800
- https://www.youtube.com/watch?v=ebmW42YYveI # "CVEs in Windows Event Logs? What You Need to Know" by 13Cubed.
- https://nullsec.us/windows-event-log-audit-cve/
author: Florian Roth (Nextron Systems), Zach Mathis
date: 2020-01-15
modified: 2022-10-22
tags:
- attack.execution
- attack.stealth
- attack.t1203
- attack.privilege-escalation
- attack.t1068
- attack.t1211
- attack.credential-access
- attack.t1212
- attack.lateral-movement
- attack.t1210
- attack.impact
- attack.t1499.004
logsource:
product: windows
service: application
detection:
selection:
Provider_Name:
- 'Microsoft-Windows-Audit-CVE'
- 'Audit-CVE'
EventID: 1
condition: selection
falsepositives:
- Unknown
level: critical
False positives
- Unknown
Source references
Connected ecosystem references
Exact source-tagged techniques
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1211 · Exploitation for Stealth · Detection rules & anomalies
- T1212 · Exploitation for Credential Access · Detection rules & anomalies
- T1499.004 · Application or System Exploitation · Detection rules & anomalies
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.