{"id":"9a025188-6f2d-42f8-bb2f-d3a83d24a5af","title":"Windows AppX Deployment Unsigned Package Installation","description":"Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-03","modified":"","tags":["attack.execution","attack.defense-impairment","attack.t1204.002","attack.t1553.005"],"technique_ids":["T1204.002","T1553.005"],"logsource":{"product":"windows","service":"appxdeployment-server"},"falsepositives":["Legitimate installation of unsigned packages for legitimate purposes such as development or testing"],"references":["https://docs.microsoft.com/en-us/powershell/module/appx/add-appxpackage","https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"source_path":"rules/windows/builtin/appxdeployment_server/win_appxpackaging_server_unsigned_package_installation.yml","source_sha256":"8cf6f67f9d1ccad7d9e20c86a318f67dbc054d00a29a76a7db4646d7014428c2","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/appxdeployment_server/win_appxpackaging_server_unsigned_package_installation.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Windows AppX Deployment Unsigned Package Installation\nid: 9a025188-6f2d-42f8-bb2f-d3a83d24a5af\nrelated:\n    - id: 37651c2a-42cd-4a69-ae0d-22a4349aa04a\n      type: similar\n    - id: 975b2262-9a49-439d-92a6-0709cccdf0b2\n      type: similar\nstatus: experimental\ndescription: Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events\nreferences:\n    - https://docs.microsoft.com/en-us/powershell/module/appx/add-appxpackage\n    - https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html\nauthor: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)\ndate: 2025-11-03\ntags:\n    - attack.execution\n    - attack.defense-impairment\n    - attack.t1204.002\n    - attack.t1553.005\nlogsource:\n    product: windows\n    service: appxdeployment-server\ndetection:\n    selection:\n        EventID: 603\n        Flags: '8388608'\n    condition: selection\nfalsepositives:\n    - Legitimate installation of unsigned packages for legitimate purposes such as development or testing\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1204.002","id":"T1204.002","name":"Malicious File","page":"techniques/enterprise/T1204.002/"},{"key":"enterprise/T1553.005","id":"T1553.005","name":"Mark-of-the-Web Bypass","page":"techniques/enterprise/T1553.005/"}],"data_path":"data/detection-rules/9a025188-6f2d-42f8-bb2f-d3a83d24a5af.json","kind":"sigma"}
