Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Msiexec execution of an executable from an uncommon remote location Informational 3 variations

    Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    7 Days
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: System Binary Proxy Execution: Msiexec (T1218.007)
    Required data: XDR Agent
    Detector tags: LOLBIN Execution Analytics
    Attacker's goals: Evading security controls and executing arbitrary files from the web.
    Investigative actions: Monitor the command-line arguments of msiexec.exe, For example, the command line - msiexec /i http://some_domain.com/www/executable.msi can be legitimate or malicious. Validate the following criteria, if none of them are correct, follow incident response procedures: Check execution of msiexec and the IP/Domain that used. Is the URL that is encoded in the command line trusted. Is executed DLL or MSI file known as legitimate. Is the initiating process legitimate and the user running it knows of its use.

    Variations

    Msiexec execution of an executable from an uncommon remote location by an RMM tool

    High overridden

    Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. This process was executed by a Remote Monitoring & Management tool. overridden

    Msiexec execution of an executable from an uncommon remote location with a specific port

    High overridden

    Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. overridden

    Msiexec execution of an executable from an uncommon remote location without properties

    Medium overridden

    Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Execution without properties is more common in malware. overridden