AppX Located in Unusual Directory Added to Deployment Pipeline (via appxdeployment-server)
This rule detects an appx package that was added to the pipeline of the "to be processed" packages that is located in uncommon locations.
SigmamediumWindowsv1
sigma
appx-located-in-unusual-directory-added-to-deployment-pipeline-via-appxdeployment-server
title: AppX Located in Unusual Directory Added to Deployment Pipeline (via appxdeployment-server)
id: 5748b9fb-3629-58ea-b259-7ba18949cde4
status: stable
description: This rule detects an appx package that was added to the pipeline of the "to be processed" packages that is located in uncommon locations.
references:
- Internal Research
- https://www.sentinelone.com/labs/inside-malicious-windows-apps-for-malware-deployment/
- https://learn.microsoft.com/en-us/windows/win32/appxpkg/troubleshooting
- https://news.sophos.com/en-us/2021/11/11/bazarloader-call-me-back-attack-abuses-windows-10-apps-mechanism/
author: Huntrule Team
date: 2026-05-04
tags:
- attack.stealth
- attack.defense-evasion
- attack.t1036
logsource:
product: windows
service: appxdeployment-server
detection:
selection:
EventID: 854
filter_main_generic:
Path|contains:
- ':/Program%20Files'
- ':/Windows/System32/'
- ':\Program Files (x86)\'
- ':\Program Files\'
- ':\Windows\ImmersiveControlPanel\'
- ':\Windows\PrintDialog\'
- ':\Windows\SystemApps\'
- 'AppData/Local/Temp/WinGet/Microsoft.Winget.Source'
- 'x-windowsupdate://'
filter_main_specific:
Path|contains:
- 'https://installer.teams.static.microsoft/'
- 'https://res.cdn.office.net'
- 'https://statics.teams.cdn.live.net/'
- 'https://statics.teams.cdn.office.net/'
- 'microsoft.com'
filter_optional_onedrive:
Path|contains: 'AppData\Local\Microsoft\OneDrive\'
filter_optional_winget:
Path|contains:
- 'AppData/Local/Temp/WinGet/Microsoft.Winget.Source'
- 'AppData\Local\Temp\WinGet\Microsoft.Winget.Source'
filter_optional_x_windowsupdate:
Path|contains: 'x-windowsupdate://'
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.