Windows AppX Deployment Full Trust Package Installation


Description

Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions

Query · sigma

selection:
  EventID: 400
  HasFullTrust: true
filter_main_legitpath:
  PackageSourceUri|startswith:
  - file:///C:/Program%20Files/
  - file:///C:/Program%20Files%20(x86)/
filter_main_microsoft:
- PackageSourceUri|startswith: https://go.microsoft.com/fwlink/?linkid
- PackageSourceUri|contains:
  - .cdn.microsoft.com
  - .cdn.office.net/
filter_main_callerprocess:
  CallingProcess|startswith:
  - sysprep.exe
  - svchost.exe,AppReadiness
filter_optional_x_update:
  PackageSourceUri|startswith: x-windowsupdate://
filter_optional_microsoftclient:
  PackageFullName|startswith: MicrosoftWindows.Client.
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*

Known false positives

  • Some legitimate applications installation which have been missed from filtering can generate fps, thus baselining and tuning is recommended before deploying to production
Raw source Windows AppX Deployment Full Trust Package Installation · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Windows AppX Deployment Full Trust Package Installation
id: e54279c7-4910-4e2c-902c-c56a25b549f6
status: experimental
description: Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
references:
    - https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html
author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-11-03
tags:
    - attack.execution
    - attack.defense-impairment
    - attack.t1204.002
    - attack.t1553.005
logsource:
    product: windows
    service: appxdeployment-server
detection:
    selection:
        EventID: 400
        HasFullTrust: true
    filter_main_legitpath:
        PackageSourceUri|startswith:
            - 'file:///C:/Program%20Files/'
            - 'file:///C:/Program%20Files%20(x86)/'
    filter_main_microsoft:
        - PackageSourceUri|startswith: 'https://go.microsoft.com/fwlink/?linkid'
        - PackageSourceUri|contains:
              - '.cdn.microsoft.com'
              - '.cdn.office.net/'
    filter_main_callerprocess:
        CallingProcess|startswith:
            - 'sysprep.exe'
            - 'svchost.exe,AppReadiness'
    filter_optional_x_update:
        PackageSourceUri|startswith: 'x-windowsupdate://'
    filter_optional_microsoftclient:
        PackageFullName|startswith: 'MicrosoftWindows.Client.'
    condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
    - Some legitimate applications installation which have been missed from filtering can generate fps, thus baselining and tuning is recommended before deploying to production
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.