Detection rules › Sigma

Potential Malicious AppX Package Installation Attempts

Severity
medium
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects potential installation or installation attempts of known malicious appx packages

Event coverage

ProviderEvent IDTitle
AppXDeployment-Server400Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path finished successfully.
AppXDeployment-Server401Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path failed with error ErrorCode.

Stages and Predicates

Stage 1: selection

PackageFullName|contains: '3669e262-ec02-4e9d-bcb4-3d008b4afac9'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
PackageFullNamematch
  • 3669e262-ec02-4e9d-bcb4-3d008b4afac9