Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
FreeReviewedSigma · High · v2
- Product
- windows
- Service
- appxdeployment-server
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-01-11
- Updated
- 2026-07-31
What it detects
This rule flags AppX packages added to the “to be processed” pipeline when their package path contains indicators of file sharing or CDN domains. Attackers can use these public hosting services to stage and deliver AppX payloads while blending into normal download patterns. It relies on Windows AppX deployment server telemetry for EventID 854 and matching the recorded package Path against a set of domain and file indicator substrings.
Reporting behind it
- sentinelone.comhttps://www.sentinelone.com/labs/inside-malicious-windows-apps-for-malware-deployment/
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/appxpkg/troubleshooting
- news.sophos.comhttps://news.sophos.com/en-us/2021/11/11/bazarloader-call-me-back-attack-abuses-windows-10-apps-mechanism/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/appxdeployment_server/win_appxdeployment_server_appx_downloaded_from_file_sharing_domains.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-appx-deployment-server-remote-appx-package-downloaded-from-file-sharing--8b48ad89
title: Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
id: bcf4d973-0243-4dac-a367-e10c01476408
related:
- id: d635249d-86b5-4dad-a8c7-d7272b788586
type: similar
- id: 52182dfb-afb7-41db-b4bc-5336cb29b464
type: similar
- id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
type: similar
- id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
type: similar
- id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
type: similar
- id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
type: similar
- id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
type: similar
- id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
type: similar
- id: b6e04788-29e1-4557-bb14-77f761848ab8
type: similar
- id: a0d7e4d2-bede-4141-8896-bc6e237e977c
type: similar
- id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
type: similar
- id: 8b48ad89-10d8-4382-a546-50588c410f0d
type: derived
status: test
description: This rule flags AppX packages added to the “to be processed” pipeline when their package path contains indicators of file sharing or CDN domains. Attackers can use these public hosting services to stage and deliver AppX payloads while blending into normal download patterns. It relies on Windows AppX deployment server telemetry for EventID 854 and matching the recorded package Path against a set of domain and file indicator substrings.
references:
- https://www.sentinelone.com/labs/inside-malicious-windows-apps-for-malware-deployment/
- https://learn.microsoft.com/en-us/windows/win32/appxpkg/troubleshooting
- https://news.sophos.com/en-us/2021/11/11/bazarloader-call-me-back-attack-abuses-windows-10-apps-mechanism/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/appxdeployment_server/win_appxdeployment_server_appx_downloaded_from_file_sharing_domains.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-01-11
modified: 2026-03-29
tags:
- attack.stealth
logsource:
product: windows
service: appxdeployment-server
detection:
selection:
EventID: 854
Path|contains:
- .githubusercontent.com
- 0x0.st
- anonfiles.com
- bashupload.com
- cdn.discordapp.com
- chunk.io
- ddns.net
- dl.dropboxusercontent.com
- ghostbin.co
- github.com
- glitch.me
- gofile.io
- hastebin.com
- mediafire.com
- mega.nz
- onrender.com
- pages.dev
- paste.ee
- pastebin.com
- pastebin.pl
- pastetext.net
- privatlab.com
- privatlab.net
- send.exploit.in
- sendspace.com
- storage.googleapis.com
- storjshare.io
- supabase.co
- temp.sh
- transfer.sh
- trycloudflare.com
- ufile.io
- w3spaces.com
- workers.dev
- x0.at
condition: selection
falsepositives:
- Unlikely, unless the organization uses file sharing or CDN services to distribute internal applications.
level: high
license: DRL-1.1