1200KM / simulation
T1218.007 Msiexec — Attack Simulation
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft. Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Since it may be signed and native on Windows…
Technique description
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft. Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Since it may be signed and native on Windows…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Msiexec.exe - Execute the DllRegisterServer function of a DLL
Procedure 0106ffa5-fab6-4c7d-82e3-e6b8867d5e5d; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WMI Win32_Product Class - Execute Local MSI file with an embedded DLL
Procedure 32eb3861-30da-4993-897a-42737152f5f8; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Msiexec.exe - Execute Remote MSI file
Procedure 44a4bedf-ffe3-452e-bee4-6925ab125662; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WMI Win32_Product Class - Execute Local MSI file with an embedded EXE
Procedure 55080eb0-49ae-4f55-a440-4167b7974f79; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Msiexec.exe - Execute Local MSI file with an embedded DLL
Procedure 628fa796-76c5-44c3-93aa-b9d8214fd568; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WMI Win32_Product Class - Execute Local MSI file with embedded JScript
Procedure 882082f0-27c6-4eec-a43c-9aa80bccdb30; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Msiexec.exe - Execute Local MSI file with embedded VBScript
Procedure 8d73c7b0-c2b1-4ac1-881a-4aa644f76064; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Msiexec.exe - Execute Local MSI file with embedded JScript
Procedure a059b6c4-e7d6-4b2e-bcd7-9b2b33191a04; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Msiexec.exe - Execute the DllUnregisterServer function of a DLL
Procedure ab09ec85-4955-4f9c-b8e0-6851baf4d47f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WMI Win32_Product Class - Execute Local MSI file with embedded VBScript
Procedure cf470d9a-58e7-43e5-b0d2-805dffc05576; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Msiexec.exe - Execute Local MSI file with an embedded EXE
Procedure ed3fa08a-ca18-4009-973e-03d13014d0e8; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.