Skip to content
Threat Feed
medium advisory

Detection of AppLocker Policy Bypass Attempts

This detection identifies potential defense evasion and privilege escalation by monitoring Windows AppLocker for repeated execution block events indicating unauthorized software usage.

Windows AppLocker is an application control feature designed to restrict the execution of unauthorized software. Threat actors attempting to escalate privileges or establish persistence often attempt to execute binaries, scripts, or installers that are explicitly blocked by security policies. When these attempts occur, AppLocker generates specific operational logs.

This threat brief focuses on identifying repeated AppLocker block events (Event IDs 8007, 8004, 8022, 8025, 8029, and 8040). An accumulation of five or more block events on a single host serves as a high-fidelity indicator that an unauthorized user or process is attempting to circumvent established security boundaries. Defenders should monitor for these events to detect potential reconnaissance or exploitation attempts where an adversary is testing policy restrictions or attempting to execute malicious payloads in a restricted environment.

Impact

Successful bypass of application control policies can allow adversaries to execute unauthorized tools, escalate privileges, or maintain persistence on compromised endpoints. Repeated attempts indicate persistent effort to circumvent security controls, which often precedes malicious activity such as credential theft or data exfiltration.

Recommendation

Detection engineering teams should ingest Microsoft-Windows-AppLocker/EXE and DLL, MSI and Script, and Packaged app-Deployment operational event logs into their SIEM.

  • Deploy the provided Sigma rule to alert on hosts where AppLocker block events exceed a threshold of five occurrences within the ingestion window.
  • Investigate the associated FilePath and TargetUser fields to determine if the activity represents a legitimate user error or a deliberate attempt to bypass security policies.
  • Tune the threshold based on the baseline volume of legitimate blocked execution attempts in the environment.

Immediate actions

Deploy Sigma detection and monitor for hosts exceeding the event threshold.

Detection Engineering 48h

Mitigations

Review AppLocker policies to ensure least privilege and account for legitimate business software.

medium_term IT Operations

Detection coverage 1

Detect Repeated AppLocker Policy Block Events

medium

Detects 5 or more AppLocker block events on a single host within the event log timeframe, indicating potential policy bypass attempts.

sigma tactics: defense_evasion techniques: T1218 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →