Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution

Alerts on AppLocker event IDs showing blocked execution of apps, scripts, DLLs, MSI, or packaged apps.

FreeReviewedSigma · Medium · v2
Product
windows
Service
applocker
Author
Pushkarev Dmitry (SigmaHQ), DRL 1.1
Published
2020-06-28
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows AppLocker events where execution is prevented for an application, DLL, script, MSI, or packaged app. Blocking execution is a key control that can stop attempted payload execution, but attackers may probe or retry blocked paths. The detection relies on AppLocker telemetry from events matching the configured AppLocker EventIDs (8004, 8007, 8022, 8025).

Related detections9 linkedT1059.005 — drag to rearrange
Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Malicious Excel Macro Spawning Scripting Interpreter Downloader (via process_creation)
Linux process execution indicators for TanStack preinstall supply-chain payloads
Windows: Koadic Command Prompt Invocation with /q /c chcp
Suspicious Wscript Spawning Embedded Python Interpreter (via process_creation)
Suspicious PowerShell Spawned by cscript in Script Chain
Suspicious Script Host Execution of Decoy-Named JavaScript Dropper (PS1Bot)
Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Pivot detection · T1059.005 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.