Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes
Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.
FreeReviewedSigma · Medium · v2
- Product
- windows
- Category
- file_event
- Author
- X__Junior (SigmaHQ), DRL 1.1
- Published
- 2025-02-07
- Updated
- 2026-07-31
What it detects
This rule flags file creation activity under the Windows Code Integrity policy directory, which can indicate WDAC policy being generated or updated. Attackers may abuse WDAC policy deployment to impede defensive tooling (e.g., EDR/AV) by restricting code execution while their own code remains allowed. The detection relies on file event telemetry for TargetFilename, along with process Image and CommandLine-based exclusions to reduce benign deployments.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-using-group-policy
- beierle.winhttps://beierle.win/2024-12-20-Weaponizing-WDAC-Killing-the-Dreams-of-EDR/
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/appcontrol-deployment-guide
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-with-script
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-with-memcm
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_wdac_policy_creation.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
windows-file-events-suspicious-wdac-policy-file-creation-in-codeintegrity-path-1d2de8a6
title: "Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes"
id: 19fab3c4-fe8b-4d7b-9e49-c95963c45cda
status: experimental
description: This rule flags file creation activity under the Windows Code Integrity policy directory, which can indicate WDAC policy being generated or updated. Attackers may abuse WDAC policy deployment to impede defensive tooling (e.g., EDR/AV) by restricting code execution while their own code remains allowed. The detection relies on file event telemetry for TargetFilename, along with process Image and CommandLine-based exclusions to reduce benign deployments.
references:
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-using-group-policy
- https://beierle.win/2024-12-20-Weaponizing-WDAC-Killing-the-Dreams-of-EDR/
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/appcontrol-deployment-guide
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-with-script
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-with-memcm
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_wdac_policy_creation.yml
author: X__Junior, Huntrule Team
date: 2025-02-07
modified: 2026-05-18
tags:
- attack.defense-impairment
logsource:
category: file_event
product: windows
detection:
selection_target:
TargetFilename|contains: \Windows\System32\CodeIntegrity\
filter_main_images:
Image|endswith:
- \Microsoft.ConfigurationManagement.exe
- \WDAC Wizard.exe
- C:\Program Files\PowerShell\7-preview\pwsh.exe
- C:\Program Files\PowerShell\7\pwsh.exe
- C:\Windows\System32\dllhost.exe
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe
- C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
- C:\Windows\SysWOW64\dllhost.exe
- C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe
- C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
filter_main_cli:
- CommandLine|contains|all:
- ConvertFrom-CIPolicy -XmlFilePath
- "-BinaryFilePath "
- CommandLine|contains: CiTool --update-policy
- CommandLine|contains|all:
- Copy-Item -Path
- -Destination
filter_main_system:
Image: System
filter_main_wuauclt:
Image: C:\Windows\System32\wuauclt.exe
filter_main_wuaucltcore:
Image:
- C:\Windows\UUS\arm64\wuaucltcore.exe
- C:\Windows\UUS\Packages\Preview\arm64\wuaucltcore.exe
condition: selection_target and not 1 of filter_main_*
falsepositives:
- Administrators and security vendors could leverage WDAC, apply additional filters as needed.
level: medium
license: DRL-1.1
related:
- id: 1d2de8a6-4803-4fde-b85b-f58f3aa7a705
type: derived