Sysmon signature verification error

Anonymous
2025-04-17T11:42:25.85+00:00

We use Sysmon to monitor events on our Windows 10 endpoinds. We randomly get Sysmon signature verification error, which occurs on 30% of endpoints regardless of their amount of RAM or build number. The example of an error:

<13>Mar 27 15:57:19 XXXXX AgentDevice=WindowsLog        AgentLogFile=Microsoft-Windows-Sysmon/Operational        PluginVersion=WC.MSEVEN6.10.1.10.11   Source=Microsoft-Windows-Sysmon  Computer=XXXXX.xxx.xxx.xxx.ua  OriginatingComputer=x.x.x.x        User=SYSTEM    Domain=NT AUTHORITY    EventID=7        EventIDCode=7  EventType=4    EventCategory=7        RecordNumber=3290522   TimeGenerated=1743083836        TimeWritten=1743083836 Level=Informational    Keywords=0        Task=SysmonTask-SYSMONEVENT_IMAGE_LOAD Opcode=Resume        Message=Image loaded: RuleName: - UtcTime: 2025-03-27 13:57:16.666 ProcessGuid: {096ac3aa-593c-67e5-7201-000000005401} ProcessId: 8968 Image: C:\Windows\System32\taskhostw.exe ImageLoaded: C:\Windows\System32\msasn1.dll FileVersion: 10.0.19041.3636 (WinBuild.160101.0800) Description: ASN.1 Runtime APIs Product: Microsoft® Windows® Operating System Company: Microsoft Corporation OriginalFileName: msasn1.dll Hashes: SHA1=FCB93A019377C297088B8EF6A1215DEC3E732D81,MD5=AB9535AEBFD8DED1BA9743A1A33C8344,SHA256=A40B90479BEF00F51B15E02D8CCE799A15248237EB68E73A2732C0FA8461BBB6,IMPHASH=F79599CA729D557E0381EC0A41471A27 Signed: failed: Signing queue is full Signature: - SignatureStatus: - User: YYYY\xxxxxxx

How can we get rid of these errors? Thanks in advance.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,239 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Alex Mihaiuc 256 Reputation points Microsoft Employee
    2025-05-08T17:51:11.0733333+00:00

    This is related to an internal queue of images that need to be verified by Sysmon. This check is computationally expensive, so if the queue is full, then Sysmon just gives up trying to validate the image signature state.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.