Skip to content
AppLocker

AppLocker Event ID 8006: Script or MSI would be blocked

File was allowed to run but would have been prevented from running if the AppLocker policy were enforcedAppLocker event 8006 records a script or MSI that ran but would have been blocked if the policy were enforced — audit-mode view of unapproved scripts.
8006
Event ID
8006
Channel
Microsoft-Windows-AppLocker/MSI and Script
Provider
Microsoft-Windows-AppLocker
Log file
Microsoft-Windows-AppLocker%4EXE and DLL.evtx
Category
Application control
Default logging
Needs configuration

What event 8006 means

Event 8006 is written to the AppLocker MSI and Script log when the Script or Windows Installer rule collection is in Audit only mode and a file outside the allow rules is run. Execution proceeds; the event records the policy violation.

In audit deployments this is a list of every script and installer that falls outside the baseline: PowerShell scripts in user profiles, batch files dropped in temp folders, .vbs and .js files opened from downloads. Those are common first-stage payloads, so 8006 is worth reviewing even when nobody plans to enforce the policy.

A well-known source of noise is PowerShell itself: at startup it writes small test scripts named __PSScriptPolicyTest_*.ps1 to the temp folder to detect the policy, and these show up here.

When it is logged

Audit policy / configuration

An AppLocker policy with Windows Installer and/or Script rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged only when the rule collection is in Audit only mode.

Script rules are checked by the script hosts themselves (PowerShell, Windows Script Host, the command processor). When script rules are enforced, PowerShell sessions run in Constrained Language Mode and only allowed scripts run in Full Language mode. AppLocker enforcement depends on the Windows edition; unsupported editions log 8009 instead.

Key fields

FieldWhat it tells you
PolicyNameRule collection that evaluated the file.
ValueMeaning
MSIWindows Installer rules (.msi, .msp, .mst).
SCRIPTScript rules (.ps1, .bat, .cmd, .vbs, .js).
RuleIdGUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny.
RuleNameName of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched.
RuleSddlSecurity descriptor of the rule, showing which user or group SID the rule applies to.
TargetUserSID of the user who tried to run the file.
TargetProcessIdID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1.
TargetLogonIdLogon session of the user; pivot to Security 4624 and 4688 with the same logon ID.
FilePathPath of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\....
FullFilePathThe same path in plain form (C:\Users\...). Present on current Windows versions.
FileHashAppLocker hash of the file, used by file hash rules.
FqbnFully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files.

Common benign sources

  • PowerShell's __PSScriptPolicyTest_*.ps1 probe files in %TEMP%.
  • Scripts and per-user installers from legitimate software not yet covered by rules.

What attackers do that produces it

  • Script-based first-stage payloads (.js, .vbs, .ps1, .bat) run from Downloads, AppData or Temp.
  • Malicious .msi packages run from user-writable locations.

Investigation tips

  • Filter out the __PSScriptPolicyTest_ files, then review the remaining paths.
  • Correlate with PowerShell 4104 and process creation (wscript, cscript, mshta, msiexec, powershell) at the same time.
  • Collect the script by FullFilePath and check its hash.

MITRE ATT&CK techniques

TechniqueTactics
T1059.001 Command and Scripting Interpreter: PowerShellExecution
T1059.005 Command and Scripting Interpreter: Visual BasicExecution
T1218.007 System Binary Proxy Execution: MsiexecStealth
T1204.002 User Execution: Malicious FileExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading