Windows winget AppInstaller admin_settings registry modification via winget.exe

Detects winget.exe-driven changes to AppInstaller admin_settings in the registry under LocalState\admin_settings.

FreeReviewedSigma · Low · v1
Product
windows
Category
registry_set
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-17
Updated
2026-07-30

What it detects

This rule flags registry writes where winget.exe is the initiating process and the target is the AppInstaller admin_settings stored under the LocalState\admin_settings path. Attackers can use these configuration changes to weaken installation controls, such as enabling local manifests or disabling installer hash checks. The detection relies on Windows registry set events that include the process image path and the registry key being modified.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.