Code Integrity Event ID 3077: App Control (WDAC) block
- Event ID
- 3077
- Channel
- Microsoft-Windows-CodeIntegrity/Operational
- Provider
- Microsoft-Windows-CodeIntegrity
- Log file
- Microsoft-Windows-CodeIntegrity%4Operational.evtx
- Category
- Application control
- Default logging
- Logged by default
What event 3077 means
Event 3077 is written to Microsoft-Windows-CodeIntegrity/Operational when an enforced App Control for Business (formerly WDAC) policy blocks an executable, DLL or driver. It is the enforcement counterpart of 3076, which reports what an audit-mode policy would have blocked. Each block is followed by one or more 3089 events carrying the file's signature information, linked by the Correlation ActivityID.
The record names the blocked file and the process that tried to load it, the requested and validated signing levels, the file hashes, the version resource (OriginalFileName, product and description) and the policy responsible (PolicyName, PolicyID, PolicyGUID). That is enough to tell whether a block is a missing allow rule for a legitimate app or an actual attack stopped by policy.
The Microsoft vulnerable driver blocklist is also enforced through App Control, so 3077 is where a blocked bring-your-own-vulnerable-driver attempt shows up.
When it is logged
An App Control for Business policy in enforced mode (custom policy, or the vulnerable driver blocklist). The CodeIntegrity/Operational log itself is enabled by default.
File and process names use field names containing spaces in some builds (e.g. File Name, Process Name) and device paths such as \Device\HarddiskVolume3\....
Key fields
| Field | What it tells you |
|---|---|
| PolicyName | Name of the policy that blocked the file. |
| PolicyID | Policy ID string from the policy's settings. |
| PolicyGUID | GUID of the policy; identifies base or supplemental policy files. |
| OriginalFileName | Original file name from the version resource; survives renaming of the binary. |
| Status | NTSTATUS result of the validation. |
Common benign sources
- Legitimate software not yet covered by allow rules after deploying or updating a policy.
- Old drivers on the vulnerable driver blocklist still installed on the system.
What attackers do that produces it
- Attempts to run unapproved tools or payloads on hosts with enforced App Control.
- BYOVD — loading a known vulnerable signed driver to kill EDR — blocked by the driver blocklist.
- DLL side-loading attempts with unsigned DLLs.
Investigation tips
- Read the blocked file path, the loading process and
OriginalFileName; a renamed known tool is a strong signal. - Pull the SHA256 hash from the event and check it against threat intelligence and the driver blocklist.
- Join with 3089 (same Correlation ActivityID) for publisher and certificate details.
- Trace how the file arrived (Sysmon 11, 4663) and what started the loading process (4688, Sysmon 1).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighCodeIntegrity - Blocked Image/Driver Load For Policy ViolationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.