Elastic Windows Event Explorer


Publisher - Microsoft-Windows-CodeIntegrity

Event ID 3038 v2

Message:

Code Integrity started validating image header of %{FileNameBuffer} file.

Event Data:

# Name In Type
Out Type
1 FileNameLength win:UInt16 xs:unsignedShort
2 FileNameBuffer win:UnicodeString xs:string
3 SecureRequired win:HexInt32 win:HexInt32
4 RequestedSigningLevel win:UInt8 xs:unsignedByte
5 ProcessNameLength win:UInt16 xs:unsignedShort
6 ProcessNameBuffer win:UnicodeString xs:string

Observed Windows Versions:

Version: 2

Fingerprint: 7GNZHGUVVT2GE