Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore

Identifies Windows processes interacting with non-packaged app consent entries for microphone and webcam access.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2020-06-07
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security events where a process has file or object access tied to the CapabilityAccessManager ConsentStore for non-packaged microphone and webcam entries. Monitoring these paths matters because it can indicate an application requesting or using local audio/video capture permissions outside normal user workflows. It relies on Windows Security telemetry from events 4657, 4656, and 4663 and matches the targeted registry object paths containing the microphone and webcam consent store locations.

Related detections5 linkedT1123 — drag to rearrange
OpenCanary SIP Request on Honeypot Node
Linux Audio Capture via arecord and ecasound (auditd execve and memfd_create)
Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Windows Process Creation: SoundRecorder audio capture using /FILE
Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Pivot detection · T1123 · 5 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.