Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0158 — Detection of Msiexec Abuse for Local, Network, and DLL Execution
DET0158

Detection of Msiexec Abuse for Local, Network, and DLL Execution

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0445 Analytic 0445
Windows

Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=3, 22
[SuspiciousCommandlinePatterns] Patterns for identifying malicious msiexec.exe usage (e.g., UNC paths, external domains, DLL execution flags)
[SuspiciousDestinationList] List of external domains or IP ranges considered suspicious for msiexec network connections
[TimeWindow] Time range in seconds/minutes for correlating msiexec.exe execution with module load and network activity
[LegitimateMSIHashes] Hash list of MSI packages considered known-good to reduce false positives

Detected Techniques

1

Details

MITRE ID
DET0158
STIX ID
x-mitre-detection-strategy--0602b47a-d37c-4eee-ac4b-b464060945ab
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.