Skip to content

Hide Navigation Hide TOC

Add Insecure Download Source To Winget (81a0ecb5-0a41-4ba1-b2ba-c944eb92bfa2)

Detects usage of winget to add a new insecure (http) download source. Winget will not allow the addition of insecure sources, hence this could indicate potential suspicious activity (or typos)

Cluster A Galaxy A Cluster B Galaxy B Level
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Add Insecure Download Source To Winget (81a0ecb5-0a41-4ba1-b2ba-c944eb92bfa2) Sigma-Rules 1