1200KM / detection
T1218.007 Msiexec — Detection Rules
Detection workspace for T1218.007 Msiexec: 9 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- MSI Installation From Web · test · medium · {"product":"windows","service":"application"}
- PowerShell WMI Win32_Product Install MSI · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- DllUnregisterServer Function Call Via Msiexec.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious MsiExec Embedding Parent · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious Msiexec Execute Arbitrary DLL · test · medium · {"category":"process_creation","product":"windows"}
- Msiexec Quiet Installation · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Msiexec Quiet Install From Remote Location · test · medium · {"category":"process_creation","product":"windows"}
- MsiExec Web Install · test · medium · {"category":"process_creation","product":"windows"}
- Obfuscated PowerShell MSI Install via WindowsInstaller COM · experimental · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0158 Detection of Msiexec Abuse for Local, Network, and DLL Execution
AN0445 Analytic 0445
Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.