Windows winget Install from Zone.Identifier/WinGet Temp Contents Marked by Zone Transfer

Alerts on winget staging under Temp\WinGet combined with ZoneTransfer ZoneId=3 and Zone.Identifier ADS contents.

FreeReviewedSigma · High · v2
Product
windows
Category
create_stream_hash
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-18
Updated
2026-07-31

What it detects

Flags winget package installations where the payload appears to have an alternate data stream (Zone.Identifier) and originates from a ZoneTransfer-marked source. Attackers can leverage winget to install malicious software while hiding in temporary download locations under WinGet. The rule relies on create_stream_hash-style telemetry capturing Contents starting with a ZoneTransfer ZoneId=3 marker, and TargetFilename patterns pointing to \AppData\Local\Temp\WinGet\ with a :Zone.Identifier stream.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.