Title:
Windows AppX Deployment Full Trust Package Installation
Status:
experimental
Description:Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
References:
-https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-11-03
modified:None
Tags:
- -'attack.execution'
- -'attack.defense-impairment'
- -'attack.t1204.002'
- -'attack.t1553.005'
Logsource:
- product: windows
- service: appxdeployment-server
Detection:
selection:
EventID:
'400'
HasFullTrust:
'True'
filter_main_legitpath:
PackageSourceUri|startswith:
-'file:///C:/Program%20Files/'
-'file:///C:/Program%20Files%20(x86)/'
filter_main_microsoft:
PackageSourceUri|startswith:
'https://go.microsoft.com/fwlink/?linkid'
- PackageSourceUri|contains:
- '.cdn.microsoft.com'
- '.cdn.office.net/'
filter_main_callerprocess:
CallingProcess|startswith:
-'sysprep.exe'
-'svchost.exe,AppReadiness'
filter_optional_x_update:
PackageSourceUri|startswith:
'x-windowsupdate://'
filter_optional_microsoftclient:
PackageFullName|startswith:
'MicrosoftWindows.Client.'
condition:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Some legitimate applications installation which have been missed from filtering can generate fps, thus baselining and tuning is recommended before deploying to production
Level:
medium