Skip to content
Threat Feed
medium advisory

Detection of Windows AppLocker Policy Violations

This brief describes the identification of Windows AppLocker policy violations, which may indicate adversary efforts to bypass application execution controls or execute unauthorized code.

Windows AppLocker is an application control mechanism designed to restrict the software and scripts that users are permitted to run. The monitoring of AppLocker block events is essential for security operations teams to detect attempts at policy circumvention or unauthorized software execution. Adversaries often attempt to run non-approved binaries, scripts, or installer files to establish persistence or facilitate secondary payload execution.

When AppLocker is configured to block unauthorized activity, it generates specific event codes within the Microsoft-Windows-AppLocker/MSI and Script or EXE and DLL event logs. By ingesting and analyzing EventCodes 8007, 8004, 8022, 8025, 8029, and 8040, defenders can identify instances where execution requests were denied. This visibility is critical for catching defense evasion techniques where an attacker attempts to execute payloads in restricted environments, potentially preventing further system compromise or data exfiltration.

Impact

The primary impact of these events is the identification of potential policy circumvention, which could lead to unauthorized code execution, privilege escalation, or persistence if an attacker successfully finds a bypass or misconfiguration. While often benign due to administrative or user error, repeated or unusual blocks on high-value systems can indicate an active threat actor attempting to weaponize local binaries or unauthorized scripts.

Recommendation

Detection engineering teams should prioritize the ingestion of AppLocker event logs to monitor for unauthorized execution attempts.

  • Enable and ingest Windows AppLocker event logs (Microsoft-Windows-AppLocker) into the SIEM, specifically focusing on EventIDs 8007, 8004, 8022, 8025, 8029, and 8040.
  • Deploy the Sigma rule provided below to trigger alerts when AppLocker blocks execution attempts.
  • Tune the alerts to exclude known administrative maintenance windows or deployment scripts to reduce noise.
  • Investigate the associated FilePath and user context for any blocked execution events to determine if the activity represents a genuine security threat or a legitimate user error.

Immediate actions

Enable AppLocker event logging in group policy objects

IT Operations 72h

Threat Hunt

High frequency of AppLocker 8007 events from a single workstation

T1218 medium medium confidence hunt now

Data: AppLocker event logs

Mitigations

Review AppLocker policy effectiveness

short_term IT Operations

T1218

Detection coverage 1

Detect Windows AppLocker Block Events

medium

Detects attempts to execute unauthorized applications or scripts by identifying Windows AppLocker policy violation events.

sigma tactics: defense_evasion techniques: T1218 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →