Code Integrity Event ID 3033: Image blocked (signing level)
- Event ID
- 3033
- Channel
- Microsoft-Windows-CodeIntegrity/Operational
- Provider
- Microsoft-Windows-CodeIntegrity
- Log file
- Microsoft-Windows-CodeIntegrity%4Operational.evtx
- Category
- Application control
- Default logging
- Logged by default
What event 3033 means
Event 3033 is written to Microsoft-Windows-CodeIntegrity/Operational when Code Integrity refuses to load an image because its signature does not meet the signing level the loading process requires. It occurs with or without an App Control (WDAC) policy: protected processes (for example LSASS running as PPL), processes using Code Integrity Guard, and App Control policies all enforce signing levels. When App Control is the cause, a 3077 is logged alongside it, and 3089 carries the signature details.
ProcessNameBuffer is the process that attempted the load, FileNameBuffer the rejected file, and RequestedPolicy / ValidatedPolicy the signing level required versus the level the file achieved. A common benign case is a third-party security or password filter DLL that is not Microsoft-signed being refused by a protected LSASS. Microsoft also notes revoked signatures and expired Lifetime Signing certificates as frequent causes.
From an attacker's perspective, 3033 is the trace left when an injection or DLL-loading technique runs into a protected process — for example an unsigned DLL pushed into LSASS, or a malicious SSP / authentication package that fails to load.
When it is logged
Microsoft-Windows-CodeIntegrity/Operational log, enabled by default.
Its audit-mode equivalent is 3034. Antivirus and other third-party products trigger 3033 frequently; baseline before alerting.
Key fields
| Field | What it tells you | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ProcessNameBuffer | Process that attempted to load the file, e.g. \Device\HarddiskVolume3\Windows\System32\lsass.exe. | ||||||||||||||
| FileNameBuffer | File that was rejected (device path form). | ||||||||||||||
| RequestedPolicy | Signing level the process required.
| ||||||||||||||
| ValidatedPolicy | Signing level the file actually achieved (same scale); 1 means unsigned or no valid signature. | ||||||||||||||
| Status | NTSTATUS code of the failed validation. |
Common benign sources
- Third-party antivirus, backup or password filter DLLs refused by LSASS running as a protected process.
- Graphics, audio or overlay DLLs refused by browsers and Office processes that enforce signing (Code Integrity Guard).
- Files with revoked or expired Lifetime Signing certificates.
What attackers do that produces it
- Attempts to load an unsigned DLL into LSASS — malicious SSPs, authentication packages or credential-dumping injection — blocked by LSA protection.
- DLL side-loading or injection into processes that require Microsoft-signed modules.
Investigation tips
- Focus on
ProcessNameBuffer=lsass.exeand onFileNameBufferin user-writable or unusual paths. - Retrieve the file, check its signature and hash, and find how it got there (Sysmon 11, 4663).
- Look for the registry change that tried to register it (LSA
Security Packages,Notification Packages) in Sysmon 13 or 4657. - If App Control is deployed, read the matching 3077 and 3089 for policy and signer details.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowCodeIntegrity - Unmet Signing Level Requirements By File Under ValidationRule by Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.