XBAP Execution From Uncommon Locations Via PresentationHost.EXE
Description
Detects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL
Query · sigma
selection_img: - Image|endswith: \presentationhost.exe - OriginalFileName: PresentationHost.exe selection_cli: CommandLine|contains: .xbap filter_main_generic: CommandLine|contains: - ' C:\Windows\' - ' C:\Program Files' condition: all of selection* and not 1 of filter_main_*
Known false positives
- Legitimate ".xbap" being executed via "PresentationHost"