AppLocker Event ID 8007: MSI or script blocked
- Event ID
- 8007
- Channel
- Microsoft-Windows-AppLocker/MSI and Script
- Provider
- Microsoft-Windows-AppLocker
- Log file
- Microsoft-Windows-AppLocker%4EXE and DLL.evtx
- Category
- Application control
- Default logging
- Needs configuration
What event 8007 means
Event 8007 is written to the AppLocker MSI and Script log when the Script or Windows Installer rule collection is in Enforce rules mode and a file is denied. The script host or Windows Installer refused to run it.
Script blocks are a strong early-warning signal: phishing chains frequently deliver .js, .vbs, .ps1 or .bat files, and an 8007 means the chain was stopped at that step. The next question is whether the attacker switched to something the policy allows, such as an interactive command, a signed binary or an inline PowerShell command.
As with 8006, PowerShell's own __PSScriptPolicyTest_*.ps1 probe files can appear here and are harmless.
When it is logged
An AppLocker policy with Windows Installer and/or Script rules — Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker — and the Application Identity service (AppIDSvc) running. Logged only when the rule collection is in Enforce rules mode.
Script rules are checked by the script hosts themselves (PowerShell, Windows Script Host, the command processor). When script rules are enforced, PowerShell sessions run in Constrained Language Mode and only allowed scripts run in Full Language mode. AppLocker enforcement depends on the Windows edition; unsupported editions log 8009 instead.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| PolicyName | Rule collection that evaluated the file.
| ||||||
| RuleId | GUID of the AppLocker rule that matched. An all-zero GUID means no rule matched and the file fell under the implicit deny. | ||||||
| RuleName | Name of the matching rule (for example (Default Rule) All files located in the Windows folder), or - when none matched. | ||||||
| RuleSddl | Security descriptor of the rule, showing which user or group SID the rule applies to. | ||||||
| TargetUser | SID of the user who tried to run the file. | ||||||
| TargetProcessId | ID of the process involved in the execution attempt; correlate with Security 4688 or Sysmon 1. | ||||||
| TargetLogonId | Logon session of the user; pivot to Security 4624 and 4688 with the same logon ID. | ||||||
| FilePath | Path of the file written with AppLocker path variables, e.g. %OSDRIVE%\USERS\..., %SYSTEM32%\..., %PROGRAMFILES%\.... | ||||||
| FullFilePath | The same path in plain form (C:\Users\...). Present on current Windows versions. | ||||||
| FileHash | AppLocker hash of the file, used by file hash rules. | ||||||
| Fqbn | Fully qualified binary name from the file's signature — publisher, product, file name and version. - for unsigned files. |
Common benign sources
- PowerShell's
__PSScriptPolicyTest_*.ps1probe files in%TEMP%. - Users running scripts or installers that IT has not approved.
What attackers do that produces it
- Blocked script payloads delivered by email, web downloads or archives.
- Blocked
.msipackages used to install malware or remote access tools.
Investigation tips
- Review every 8007 whose path is not a
__PSScriptPolicyTest_file; identify the parent process that tried to run it. - Look right after the block for other execution attempts (Security 4688, Sysmon 1, PowerShell 4104, AppLocker 8002/8005).
- Collect the script by FullFilePath and trace how it arrived (browser downloads, mail attachments, Sysmon 11).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumAppLocker Prevented Application or Script from RunningRule by Pushkarev Dmitry, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.