Detection rules › Sigma

AppX Package Deployment Failed Due to Signing Requirements

Severity
medium
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects an appx package deployment / installation with the error code "0x80073cff" which indicates that the package didn't meet the signing requirements.

Event coverage

ProviderEvent IDTitle
AppXDeployment-Server401Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path failed with error ErrorCode.

Stages and Predicates

Stage 1: selection

ErrorCode: 0x80073cff

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
ErrorCodeeq
  • 0x80073cff