Analytics BIOC Medium

Windows Installer exploitation for local privilege escalation

The Windows installer (msiexec.exe) was likely exploited to run a malicious rollback script (.rbs file) instead of the original. Users should not be able to modify config.msi during the installation process, only SYSTEM should have access to it.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Exploitation for Privilege Escalation (T1068)
Attacker's goals:

An attacker is attempting to gain SYSTEM privileges.

Investigative actions:

Investigate the actor process SID and path and whether it's benign or normal for this host. This action is not common, but allowed on Windows versions older than Windows 8. On those systems, check the file reputation for both the CGO and OS actor executables that ran the installation.

Test period:
N/A (single event)
Deduplication:
1 Day