Deployment AppX Package Was Blocked By AppLocker

Detects an appx package deployment that was blocked by AppLocker policy

Sigma rule (View on GitHub)

 1title: Deployment AppX Package Was Blocked By AppLocker
 2id: 6ae53108-c3a0-4bee-8f45-c7591a2c337f
 3status: test
 4description: Detects an appx package deployment that was blocked by AppLocker policy
 5references:
 6    - https://learn.microsoft.com/en-us/windows/win32/appxpkg/troubleshooting
 7    - https://github.com/nasbench/EVTX-ETW-Resources/blob/7a806a148b3d9d381193d4a80356016e6e8b1ee8/ETWEventsList/CSV/Windows11/22H2/W11_22H2_Pro_20220920_22621.382/Providers/Microsoft-Windows-AppXDeployment-Server.csv
 8author: frack113
 9date: 2023/01/11
10tags:
11    - attack.defense_evasion
12logsource:
13    product: windows
14    service: appxdeployment-server
15detection:
16    selection:
17        EventID: 412
18    condition: selection
19falsepositives:
20    - Unknown
21level: medium

References

Related rules

to-top