Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕ technique: T1218 ✕
Download CSV Show ATT&CK heatmapUncommon msiexec execution of an arbitrary file from a remote location Low 1 variation
Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: System Binary Proxy Execution: Msiexec (T1218.007)Required data: XDR AgentDetector tags: LOLBIN Execution AnalyticsAttacker's goals: Evading security controls and executing arbitrary files from the web.Investigative actions: Monitor the command-line arguments of msiexec.exe, For example, the command line msiexec /i http://some_domain.com/www/executable.msi can be legitimate or malicious. Check if the the URL that is encoded in the command line is trusted. Determine if the executed DLL or MSI file is known as legitimate. Confirm whether the initiating process is legitimate and if the user running it knows of its use. Note - the MSI executable can run from other LAN locations, the alert will raise on the WAN connection.Variations
Suspicious msiexec execution on an internet-facing endpoint
Low overridden
Suspicious msiexec execution of an arbitrary file from the web on an internet-facing server. overridden