Windows AppX Deployment Full Trust Package Installation

 Original Source: [Sigma source]
Title: Windows AppX Deployment Full Trust Package Installation
Status: experimental
Description:Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
References:
  -https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-11-03
modified:None
Tags:
  • -'attack.execution'
  • -'attack.defense-impairment'
  • -'attack.t1204.002'
  • -'attack.t1553.005'
Logsource:
  • product: windows
  • service: appxdeployment-server
Detection:
  selection:
    EventID: '400'
    HasFullTrust: 'True'
  filter_main_legitpath:
    PackageSourceUri|startswith:
      -'file:///C:/Program%20Files/'
      -'file:///C:/Program%20Files%20(x86)/'

  filter_main_microsoft:
PackageSourceUri|startswith:'https://go.microsoft.com/fwlink/?linkid'     - PackageSourceUri|contains:
      - '.cdn.microsoft.com'
      - '.cdn.office.net/'
  filter_main_callerprocess:
    CallingProcess|startswith:
      -'sysprep.exe'
      -'svchost.exe,AppReadiness'

  filter_optional_x_update:
    PackageSourceUri|startswith: 'x-windowsupdate://'
  filter_optional_microsoftclient:
    PackageFullName|startswith: 'MicrosoftWindows.Client.'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Some legitimate applications installation which have been missed from filtering can generate fps, thus baselining and tuning is recommended before deploying to production
Level: medium