AppLocker Event ID 8005: MSI or script allowed
- Event ID
- 8005
- Channel
- Microsoft-Windows-AppLocker/MSI and Script
- Provider
- Microsoft-Windows-AppLocker
- Log file
- Microsoft-Windows-AppLocker%4EXE and DLL.evtx
- Category
- Application control
- Default logging
- Needs configuration
What event 8005 means
Event 8005 is written to the AppLocker MSI and Script log when a Windows Installer package (.msi, .msp, .mst) or a script (.ps1, .bat, .cmd, .vbs, .js) is evaluated and allowed by a rule. The data under UserData/RuleAndFileData has the same layout as the EXE events: PolicyName (MSI or SCRIPT), the rule, the user, and the file path, hash and signer.
Script checks are performed by the script hosts when they load a file, so 8005 gives a record of which script files ran and as whom — useful alongside PowerShell 4104, which shows content but not always the file on disk.
Allowed scripts from broad path rules (for example anything under C:\Windows) are where bypasses hide. Scripts from user-writable subfolders of allowed paths deserve attention.
When it is logged
An AppLocker policy with Windows Installer and/or Script rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged for allowed files in both Audit only and Enforce rules modes.
Script rules are checked by the script hosts themselves (PowerShell, Windows Script Host, the command processor). When script rules are enforced, PowerShell sessions run in Constrained Language Mode and only allowed scripts run in Full Language mode. AppLocker enforcement depends on the Windows edition; unsupported editions log 8009 instead.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| PolicyName | Rule collection that evaluated the file.
| ||||||
| RuleId | GUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny. | ||||||
| RuleName | Name of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched. | ||||||
| RuleSddl | Security descriptor of the rule, showing which user or group SID the rule applies to. | ||||||
| TargetUser | SID of the user who tried to run the file. | ||||||
| TargetProcessId | ID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1. | ||||||
| TargetLogonId | Logon session of the user; pivot to Security 4624 and 4688 with the same logon ID. | ||||||
| FilePath | Path of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\.... | ||||||
| FullFilePath | The same path in plain form (C:\Users\...). Present on current Windows versions. | ||||||
| FileHash | AppLocker hash of the file, used by file hash rules. | ||||||
| Fqbn | Fully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files. |
Common benign sources
- Logon scripts, admin scripts and management agents running scripts from approved locations.
- Software installation from approved
.msipackages.
What attackers do that produces it
- Scripts placed in writable folders that a broad allow rule covers, executed to bypass the policy.
- Malicious
.msipackages allowed by overly broad rules (for example all signed packages).
Investigation tips
- Stack FullFilePath; review scripts outside
SYSVOL,Program Filesand known admin shares. - Correlate with PowerShell 4104 (script content) and process creation (4688 / Sysmon 1) for the host process.
- Compare with 8006/8007 to see which scripts the policy did not allow.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.