Skip to content
Code Integrity

Code Integrity Event ID 3077: App Control (WDAC) block

Code Integrity determined that a process attempted to load a file that did not meet the policy requirementsCode Integrity event 3077 is the main App Control for Business (WDAC) enforcement block: a file failed the active policy and was prevented from loading.
3077
Event ID
3077
Channel
Microsoft-Windows-CodeIntegrity/Operational
Provider
Microsoft-Windows-CodeIntegrity
Log file
Microsoft-Windows-CodeIntegrity%4Operational.evtx
Category
Application control
Default logging
Logged by default

What event 3077 means

Event 3077 is written to Microsoft-Windows-CodeIntegrity/Operational when an enforced App Control for Business (formerly WDAC) policy blocks an executable, DLL or driver. It is the enforcement counterpart of 3076, which reports what an audit-mode policy would have blocked. Each block is followed by one or more 3089 events carrying the file's signature information, linked by the Correlation ActivityID.

The record names the blocked file and the process that tried to load it, the requested and validated signing levels, the file hashes, the version resource (OriginalFileName, product and description) and the policy responsible (PolicyName, PolicyID, PolicyGUID). That is enough to tell whether a block is a missing allow rule for a legitimate app or an actual attack stopped by policy.

The Microsoft vulnerable driver blocklist is also enforced through App Control, so 3077 is where a blocked bring-your-own-vulnerable-driver attempt shows up.

When it is logged

Audit policy / configuration

An App Control for Business policy in enforced mode (custom policy, or the vulnerable driver blocklist). The CodeIntegrity/Operational log itself is enabled by default.

File and process names use field names containing spaces in some builds (e.g. File Name, Process Name) and device paths such as \Device\HarddiskVolume3\....

Key fields

FieldWhat it tells you
PolicyNameName of the policy that blocked the file.
PolicyIDPolicy ID string from the policy's settings.
PolicyGUIDGUID of the policy; identifies base or supplemental policy files.
OriginalFileNameOriginal file name from the version resource; survives renaming of the binary.
StatusNTSTATUS result of the validation.

Common benign sources

  • Legitimate software not yet covered by allow rules after deploying or updating a policy.
  • Old drivers on the vulnerable driver blocklist still installed on the system.

What attackers do that produces it

  • Attempts to run unapproved tools or payloads on hosts with enforced App Control.
  • BYOVD — loading a known vulnerable signed driver to kill EDR — blocked by the driver blocklist.
  • DLL side-loading attempts with unsigned DLLs.

Investigation tips

  • Read the blocked file path, the loading process and OriginalFileName; a renamed known tool is a strong signal.
  • Pull the SHA256 hash from the event and check it against threat intelligence and the driver blocklist.
  • Join with 3089 (same Correlation ActivityID) for publisher and certificate details.
  • Trace how the file arrived (Sysmon 11, 4663) and what started the loading process (4688, Sysmon 1).

MITRE ATT&CK techniques

TechniqueTactics
T1068 Exploitation for Privilege EscalationPrivilege Escalation
T1685 Disable or Modify ToolsDefense Impairment
T1574.001 Hijack Execution Flow: DLLStealth, Execution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 3076 & 3077: WDAC Code Integrity blocks explained

Sources and further reading