Windows AppX Package Deployment: Suspicious AppX Installation Attempts by PackageFullName

Alerts on Windows AppX deployment events tied to a known-malicious AppX package identifier.

FreeReviewedSigma · Medium · v2
Product
windows
Service
appxdeployment-server
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-11
Updated
2026-07-31

What it detects

This rule flags AppX deployment server events indicating an installation or attempted installation of a specific known-bad AppX package, based on matching the PackageFullName substring. Attackers can abuse the Windows AppX mechanism to stealthily deliver and execute malicious components through the app deployment workflow. It relies on Windows telemetry from the appxdeployment-server service with EventID 400 or 401 and PackageFullName containing the marked identifier.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.