Windows AppX Deployment Failure (0x80073cff) Due to Signing Requirements

Alerts on Windows AppX deployments/installations failing with 0x80073cff, consistent with unmet signing requirements.

FreeReviewedSigma · Medium · v2
Product
windows
Service
appxdeployment-server
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-11
Updated
2026-07-31

What it detects

This rule flags AppX package deployment and installation failures on Windows when the error code is 0x80073cff, indicating the package did not meet signing requirements. Attackers may exploit or attempt to deploy unsigned or improperly signed packages to gain persistence or execute malicious components, making these failures useful for early triage. The detection relies on Windows AppX deployment server events containing EventID 401 and an ErrorCode value of 0x80073cff.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.