This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Windows AppX Deployment Unsigned Package Installation
Original Source:
[Sigma source]
Title:
Windows AppX Deployment Unsigned Package Installation
Status:
experimental
Description:
Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
References:
-https://docs.microsoft.com/en-us/powershell/module/appx/add-appxpackage
-https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html
Author:
Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2025-11-03
modified:
None
Tags:
-'attack.execution'
-'attack.defense-impairment'
-'attack.t1204.002'
-'attack.t1553.005'
Logsource:
product: windows
service: appxdeployment-server
Detection:
selection:
EventID
:
'603'
Flags
:
'8388608'
condition
:
selection
Falsepositives:
-Legitimate installation of unsigned packages for legitimate purposes such as development or testing
Level:
medium