Windows Registry: Appx DebugPath Key for Potential Persistence
Detects registry set activity involving AppX DebugPath entries that may indicate persistence via packaged app debug configuration.
FreeUnreviewedSigmamediumv1
windows-registry-appx-debugpath-key-for-potential-persistence-df4dc653
title: "Windows Registry: Appx DebugPath Key for Potential Persistence"
id: d696fbd3-e812-4323-81f9-1775e68dd443
status: test
description: This rule flags Windows registry modifications where a TargetObject containing Microsoft-related packaged app debug path entries ends with \DebugPath. It also matches entries under the PackagedAppXDebug Microsoft AppX debug key where the TargetObject ends with \(Default). Such registry persistence mechanisms can be used by attackers to influence how packaged apps are launched or debugged. Detection relies on registry set telemetry that includes TargetObject paths.
references:
- https://oddvar.moe/2018/09/06/persistence-using-universal-windows-platform-apps-appx/
- https://github.com/rootm0s/WinPwnage
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_set/registry_set_persistence_appx_debugger.yml
author: frack113, Huntrule Team
date: 2022-07-27
modified: 2023-08-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1546.015
logsource:
category: registry_set
product: windows
detection:
selection_debug:
TargetObject|contains: Classes\ActivatableClasses\Package\Microsoft.
TargetObject|endswith: \DebugPath
selection_default:
TargetObject|contains: \Software\Microsoft\Windows\CurrentVersion\PackagedAppXDebug\Microsoft.
TargetObject|endswith: \(Default)
condition: 1 of selection_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: df4dc653-1029-47ba-8231-3c44238cc0ae
type: derived
What it detects
This rule flags Windows registry modifications where a TargetObject containing Microsoft-related packaged app debug path entries ends with \DebugPath. It also matches entries under the PackagedAppXDebug Microsoft AppX debug key where the TargetObject ends with \(Default). Such registry persistence mechanisms can be used by attackers to influence how packaged apps are launched or debugged. Detection relies on registry set telemetry that includes TargetObject paths.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.