Detect Elevated Windows Installer (msiexec) Running as SYSTEM

Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.

FreeUnreviewedSigmamediumv1
title: Detect Elevated Windows Installer (msiexec) Running as SYSTEM
id: 80a002b7-a092-4358-94e6-98e25850d695
status: test
description: This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.
references:
  - https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-48-638.jpg
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_always_install_elevated_windows_installer.yml
author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule Team
date: 2020-10-13
modified: 2024-12-01
tags:
  - attack.privilege-escalation
  - attack.t1548.002
logsource:
  product: windows
  category: process_creation
detection:
  selection_user:
    User|contains:
      - AUTHORI
      - AUTORI
  selection_image_1:
    Image|contains|all:
      - \Windows\Installer\
      - msi
    Image|endswith: tmp
  selection_image_2:
    Image|endswith: \msiexec.exe
    IntegrityLevel:
      - System
      - S-1-16-16384
  filter_installer:
    ParentImage: C:\Windows\System32\services.exe
  filter_repair:
    - CommandLine|endswith: \system32\msiexec.exe /V
    - ParentCommandLine|endswith: \system32\msiexec.exe /V
  filter_sophos:
    ParentImage|startswith: C:\ProgramData\Sophos\
  filter_avira:
    ParentImage|startswith: C:\ProgramData\Avira\
  filter_avast:
    ParentImage|startswith:
      - C:\Program Files\Avast Software\
      - C:\Program Files (x86)\Avast Software\
  filter_google_update:
    ParentImage|startswith:
      - C:\Program Files\Google\Update\
      - C:\Program Files (x86)\Google\Update\
  condition: 1 of selection_image_* and selection_user and not 1 of filter_*
falsepositives:
  - System administrator usage
  - Anti virus products
  - WindowsApps located in "C:\Program Files\WindowsApps\"
level: medium
license: DRL-1.1
related:
  - id: cd951fdc-4b2f-47f5-ba99-a33bf61e3770
    type: derived

What it detects

This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.

Known false positives

  • System administrator usage
  • Anti virus products
  • WindowsApps located in "C:\Program Files\WindowsApps\"

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.