Detection rules › Sigma

Windows Update Error

Status
stable
Severity
informational
Log source
product windows, service system
Author
frack113
Source
github.com/SigmaHQ/sigma

Detects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.

MITRE ATT&CK coverage

TacticTechniques
Resource DevelopmentT1584 Compromise Infrastructure

Event coverage

Rule body yaml

title: Windows Update Error
id: 13cfeb75-9e33-4d04-b0f7-ab8faaa95a59
status: stable
description: |
    Detects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.
references:
    - https://github.com/nasbench/EVTX-ETW-Resources/blob/f1b010ce0ee1b71e3024180de1a3e67f99701fe4/ETWProvidersManifests/Windows10/1903/W10_1903_Pro_20200714_18362.959/WEPExplorer/Microsoft-Windows-WindowsUpdateClient.xml
author: frack113
date: 2021-12-04
modified: 2023-09-07
tags:
    - attack.impact
    - attack.resource-development
    - attack.t1584
logsource:
    product: windows
    service: system
detection:
    selection:
        Provider_Name: Microsoft-Windows-WindowsUpdateClient
        EventID:
            - 16 # Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule
            - 20 # Installation Failure: Windows failed to install the following update with error
            - 24 # Uninstallation Failure: Windows failed to uninstall the following update with error
            - 213 # Revert Failure: Windows failed to revert the following update with error
            - 217 # Commit Failure: Windows failed to commit the following update with error
    condition: selection
falsepositives:
    - Unknown
level: informational

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    Provider_Name: Microsoft-Windows-WindowsUpdateClient
    EventID:
        - 16
        - 20
        - 24
        - 213
        - 217

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
Provider_Nameeq
  • Microsoft-Windows-WindowsUpdateClient