Windows AppX Deployment Unsigned Package Installation

 Original Source: [Sigma source]
Title: Windows AppX Deployment Unsigned Package Installation
Status: experimental
Description:Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
References:
  -https://docs.microsoft.com/en-us/powershell/module/appx/add-appxpackage
  -https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-11-03
modified:None
Tags:
  • -'attack.execution'
  • -'attack.defense-impairment'
  • -'attack.t1204.002'
  • -'attack.t1553.005'
Logsource:
  • product: windows
  • service: appxdeployment-server
Detection:
  selection:
    EventID: '603'
    Flags: '8388608'
  condition:selection
Falsepositives:
  -Legitimate installation of unsigned packages for legitimate purposes such as development or testing
Level: medium