Windows AppX Deployment Server: Remote AppX Package Downloaded from File Sharing/CDN Domains

Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.

FreeUnreviewedSigmahighv1
title: "Windows AppX Deployment Server: Remote AppX Package Downloaded from File Sharing/CDN Domains"
id: bcf4d973-0243-4dac-a367-e10c01476408
related:
  - id: d635249d-86b5-4dad-a8c7-d7272b788586
    type: similar
  - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
    type: similar
  - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
    type: similar
  - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
    type: similar
  - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
    type: similar
  - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
    type: similar
  - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
    type: similar
  - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
    type: similar
  - id: b6e04788-29e1-4557-bb14-77f761848ab8
    type: similar
  - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
    type: similar
  - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
    type: similar
  - id: 8b48ad89-10d8-4382-a546-50588c410f0d
    type: derived
status: test
description: This rule flags Windows AppX deployment activity where the AppX package being processed is added from a pipeline source containing common file sharing or CDN-related domains. Such behavior matters because attackers can use remote package staging to deliver malicious or unauthorized AppX content. It relies on Windows AppX deployment server telemetry (EventID 854) and matches the recorded package path or source against a list of external hosting domains.
references:
  - https://www.sentinelone.com/labs/inside-malicious-windows-apps-for-malware-deployment/
  - https://learn.microsoft.com/en-us/windows/win32/appxpkg/troubleshooting
  - https://news.sophos.com/en-us/2021/11/11/bazarloader-call-me-back-attack-abuses-windows-10-apps-mechanism/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/appxdeployment_server/win_appxdeployment_server_appx_downloaded_from_file_sharing_domains.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-01-11
modified: 2026-03-29
tags:
  - attack.stealth
logsource:
  product: windows
  service: appxdeployment-server
detection:
  selection:
    EventID: 854
    Path|contains:
      - .githubusercontent.com
      - 0x0.st
      - anonfiles.com
      - bashupload.com
      - cdn.discordapp.com
      - chunk.io
      - ddns.net
      - dl.dropboxusercontent.com
      - ghostbin.co
      - github.com
      - glitch.me
      - gofile.io
      - hastebin.com
      - mediafire.com
      - mega.nz
      - onrender.com
      - pages.dev
      - paste.ee
      - pastebin.com
      - pastebin.pl
      - pastetext.net
      - privatlab.com
      - privatlab.net
      - send.exploit.in
      - sendspace.com
      - storage.googleapis.com
      - storjshare.io
      - supabase.co
      - temp.sh
      - transfer.sh
      - trycloudflare.com
      - ufile.io
      - w3spaces.com
      - workers.dev
      - x0.at
  condition: selection
falsepositives:
  - Unlikely, unless the organization uses file sharing or CDN services to distribute internal applications.
level: high
license: DRL-1.1

What it detects

This rule flags Windows AppX deployment activity where the AppX package being processed is added from a pipeline source containing common file sharing or CDN-related domains. Such behavior matters because attackers can use remote package staging to deliver malicious or unauthorized AppX content. It relies on Windows AppX deployment server telemetry (EventID 854) and matches the recorded package path or source against a list of external hosting domains.

Known false positives

  • Unlikely, unless the organization uses file sharing or CDN services to distribute internal applications.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.