Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes

Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
X__Junior (SigmaHQ), DRL 1.1
Published
2025-02-07
Updated
2026-07-31
title: "Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes"
id: 19fab3c4-fe8b-4d7b-9e49-c95963c45cda
status: experimental
description: This rule flags file creation activity under the Windows Code Integrity policy directory, which can indicate WDAC policy being generated or updated. Attackers may abuse WDAC policy deployment to impede defensive tooling (e.g., EDR/AV) by restricting code execution while their own code remains allowed. The detection relies on file event telemetry for TargetFilename, along with process Image and CommandLine-based exclusions to reduce benign deployments.
references:
  - https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-using-group-policy
  - https://beierle.win/2024-12-20-Weaponizing-WDAC-Killing-the-Dreams-of-EDR/
  - https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/appcontrol-deployment-guide
  - https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-with-script
  - https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/deployment/deploy-appcontrol-policies-with-memcm
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_susp_wdac_policy_creation.yml
author: X__Junior, Huntrule Team
date: 2025-02-07
modified: 2026-05-18
tags:
  - attack.defense-impairment
logsource:
  category: file_event
  product: windows
detection:
  selection_target:
    TargetFilename|contains: \Windows\System32\CodeIntegrity\
  filter_main_images:
    Image|endswith:
      - \Microsoft.ConfigurationManagement.exe
      - \WDAC Wizard.exe
      - C:\Program Files\PowerShell\7-preview\pwsh.exe
      - C:\Program Files\PowerShell\7\pwsh.exe
      - C:\Windows\System32\dllhost.exe
      - C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe
      - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
      - C:\Windows\SysWOW64\dllhost.exe
      - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe
      - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
  filter_main_cli:
    - CommandLine|contains|all:
        - ConvertFrom-CIPolicy -XmlFilePath
        - "-BinaryFilePath "
    - CommandLine|contains: CiTool --update-policy
    - CommandLine|contains|all:
        - Copy-Item -Path
        - -Destination
  filter_main_system:
    Image: System
  filter_main_wuauclt:
    Image: C:\Windows\System32\wuauclt.exe
  filter_main_wuaucltcore:
    Image:
      - C:\Windows\UUS\arm64\wuaucltcore.exe
      - C:\Windows\UUS\Packages\Preview\arm64\wuaucltcore.exe
  condition: selection_target and not 1 of filter_main_*
falsepositives:
  - Administrators and security vendors could leverage WDAC, apply additional filters as needed.
level: medium
license: DRL-1.1
related:
  - id: 1d2de8a6-4803-4fde-b85b-f58f3aa7a705
    type: derived