Techniques
Sample rules
Potential Malicious AppX Package Installation Attempts
- source: sigma
- technicques:
Description
Detects potential installation or installation attempts of known malicious appx packages
Detection logic
condition: selection
selection:
EventID:
- 400
- 401
PackageFullName|contains: 3669e262-ec02-4e9d-bcb4-3d008b4afac9