Windows Registry change enabling developer features for sideloading and untrusted app installs

Alerts on registry writes that enable Windows developer feature policies allowing sideloading of untrusted apps.

FreeReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-01-12
Updated
2026-07-30

What it detects

This rule flags Windows registry modifications that enable developer feature settings under AppModelUnlock and Appx policy paths. Enabling these options can allow installation of untrusted packages or bypass intended trust and licensing checks. It relies on registry set telemetry by matching TargetObject paths and a DWORD value of 0x00000001.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.