In brief

A breakdown of UWP/MSIX — in the speaker's words, computer forensics rather than incident response. The isolation UWP was conceived for disappeared after Desktop Bridge and runFullTrust, and the Microsoft Store became a delivery channel for malicious packages and a source of tooling that needs no admin rights. The second half is DFIR artifacts and a minimum of policies and detections; a technical talk, there were no questions.

Key points

Tools, artifacts, technologies

Nothing was said: no laws, no articles, no agencies, no methodologies; the speaker's terminology is "computer forensics", "incident response", "cyber exercises". On the organizational side: Microsoft disabled ms-appinstaller, but itself opened the way for unsigned packages in Windows 11; prohibition policies and the collection of events in a SIEM.

Questions from the audience

There were no questions: after "your questions, if there are any" came the joke "As always, you've broken my whole audience", and then the break until 13:10. The speakers are not labeled: by the context this is the moderator, but it is not obvious.

The speaker's position

The isolation of UWP after Desktop Bridge and runFullTrust is a formality; allowing unsigned packages in Windows 11 both weakens the system and hands the forensic expert a ready-made indicator. The tone is a lecture read off the slides, with no polemics and no sales pitch: F6's products are not named. He acknowledges the limitation of his own artifacts (only installed applications) himself, but devalues it in the same breath; he does not inflate the scale.

Quotes