1200KM / simulation
T1218.004 InstallUtil — Attack Simulation
Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\Windows\Microsoft.NET\Framework\v\InstallUtil.exe and…
Technique description
Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for installation and uninstallation of resources by executing specific installer components specified in .NET binaries. The InstallUtil binary may also be digitally signed by Microsoft and located in the .NET directories on a Windows system: C:\Windows\Microsoft.NET\Framework\v\InstallUtil.exe and…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- InstallUtil Uninstall method call - '/installtype=notransaction /action=uninstall' variant
Procedure 06d9deba-f732-48a8-af8e-bdd6e4d98c1d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- InstallUtil Uninstall method call - /U variant
Procedure 34428cfa-8e38-41e5-aff4-9e1f8f3a7b4b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- InstallUtil evasive invocation
Procedure 559e6d06-bb42-4307-bff7-3b95a8254bad; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- InstallUtil HelpText method call
Procedure 5a683850-1145-4326-a0e5-e91ced3c6022; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- InstallUtil class constructor method call
Procedure 9b7a7cfc-dd2e-43f5-a885-c0a3c270dd93; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- InstallUtil Install method call
Procedure 9f9968a6-601a-46ca-b7b7-6d4fe0f98f0b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- InstallHelper method call
Procedure d43a5bde-ae28-4c55-a850-3f4c80573503; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- CheckIfInstallable method call
Procedure ffd9c807-d402-47d2-879d-f915cf2a3a94; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.