Windows MSIX Package Support Framework AI_STUBS Execution

 Original Source: [Sigma source]
Title: Windows MSIX Package Support Framework AI_STUBS Execution
Status: experimental
Description:Detects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
References:
  -https://redcanary.com/blog/threat-intelligence/msix-installers/
  -https://redcanary.com/threat-detection-report/techniques/installer-packages/
  -https://learn.microsoft.com/en-us/windows/msix/package/package-support-framework
  -https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-11-03
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.defense-impairment'
  • -'attack.t1218'
  • -'attack.t1553.005'
  • -'attack.t1204.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\AI_STUBS\AiStubX64Elevated.exe'
      -'\AI_STUBS\AiStubX86Elevated.exe'
      -'\AI_STUBS\AiStubX64.exe'
      -'\AI_STUBS\AiStubX86.exe'

    OriginalFileName: 'popupwrapper.exe'
  condition:selection
Falsepositives:
  -Legitimate applications packaged with Advanced Installer using Package Support Framework
Level: low