Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes

Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
X__Junior (SigmaHQ), DRL 1.1
Published
2025-02-07
Updated
2026-07-31

What it detects

This rule flags file creation activity under the Windows Code Integrity policy directory, which can indicate WDAC policy being generated or updated. Attackers may abuse WDAC policy deployment to impede defensive tooling (e.g., EDR/AV) by restricting code execution while their own code remains allowed. The detection relies on file event telemetry for TargetFilename, along with process Image and CommandLine-based exclusions to reduce benign deployments.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.