Skip to content
AppLocker

AppLocker Event ID 8005: MSI or script allowed

File was allowed to runAppLocker event 8005 records that a script or Windows Installer file was allowed to run by an AppLocker rule, with the file path, rule and user SID.
8005
Event ID
8005
Channel
Microsoft-Windows-AppLocker/MSI and Script
Provider
Microsoft-Windows-AppLocker
Log file
Microsoft-Windows-AppLocker%4EXE and DLL.evtx
Category
Application control
Default logging
Needs configuration

What event 8005 means

Event 8005 is written to the AppLocker MSI and Script log when a Windows Installer package (.msi, .msp, .mst) or a script (.ps1, .bat, .cmd, .vbs, .js) is evaluated and allowed by a rule. The data under UserData/RuleAndFileData has the same layout as the EXE events: PolicyName (MSI or SCRIPT), the rule, the user, and the file path, hash and signer.

Script checks are performed by the script hosts when they load a file, so 8005 gives a record of which script files ran and as whom — useful alongside PowerShell 4104, which shows content but not always the file on disk.

Allowed scripts from broad path rules (for example anything under C:\Windows) are where bypasses hide. Scripts from user-writable subfolders of allowed paths deserve attention.

When it is logged

Audit policy / configuration

An AppLocker policy with Windows Installer and/or Script rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged for allowed files in both Audit only and Enforce rules modes.

Script rules are checked by the script hosts themselves (PowerShell, Windows Script Host, the command processor). When script rules are enforced, PowerShell sessions run in Constrained Language Mode and only allowed scripts run in Full Language mode. AppLocker enforcement depends on the Windows edition; unsupported editions log 8009 instead.

Key fields

FieldWhat it tells you
PolicyNameRule collection that evaluated the file.
ValueMeaning
MSIWindows Installer rules (.msi, .msp, .mst).
SCRIPTScript rules (.ps1, .bat, .cmd, .vbs, .js).
RuleIdGUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny.
RuleNameName of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched.
RuleSddlSecurity descriptor of the rule, showing which user or group SID the rule applies to.
TargetUserSID of the user who tried to run the file.
TargetProcessIdID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1.
TargetLogonIdLogon session of the user; pivot to Security 4624 and 4688 with the same logon ID.
FilePathPath of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\....
FullFilePathThe same path in plain form (C:\Users\...). Present on current Windows versions.
FileHashAppLocker hash of the file, used by file hash rules.
FqbnFully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files.

Common benign sources

  • Logon scripts, admin scripts and management agents running scripts from approved locations.
  • Software installation from approved .msi packages.

What attackers do that produces it

  • Scripts placed in writable folders that a broad allow rule covers, executed to bypass the policy.
  • Malicious .msi packages allowed by overly broad rules (for example all signed packages).

Investigation tips

  • Stack FullFilePath; review scripts outside SYSVOL, Program Files and known admin shares.
  • Correlate with PowerShell 4104 (script content) and process creation (4688 / Sysmon 1) for the host process.
  • Compare with 8006/8007 to see which scripts the policy did not allow.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution
T1059.005 Command and Scripting Interpreter: Visual BasicExecution
T1218.007 System Binary Proxy Execution: MsiexecStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading