Detect Elevated Windows Installer (msiexec) Running as SYSTEM
Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.
FreeUnreviewedSigmamediumv1
detect-elevated-windows-installer-msiexec-running-as-system-cd951fdc
title: Detect Elevated Windows Installer (msiexec) Running as SYSTEM
id: 80a002b7-a092-4358-94e6-98e25850d695
status: test
description: This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.
references:
- https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-48-638.jpg
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_always_install_elevated_windows_installer.yml
author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule Team
date: 2020-10-13
modified: 2024-12-01
tags:
- attack.privilege-escalation
- attack.t1548.002
logsource:
product: windows
category: process_creation
detection:
selection_user:
User|contains:
- AUTHORI
- AUTORI
selection_image_1:
Image|contains|all:
- \Windows\Installer\
- msi
Image|endswith: tmp
selection_image_2:
Image|endswith: \msiexec.exe
IntegrityLevel:
- System
- S-1-16-16384
filter_installer:
ParentImage: C:\Windows\System32\services.exe
filter_repair:
- CommandLine|endswith: \system32\msiexec.exe /V
- ParentCommandLine|endswith: \system32\msiexec.exe /V
filter_sophos:
ParentImage|startswith: C:\ProgramData\Sophos\
filter_avira:
ParentImage|startswith: C:\ProgramData\Avira\
filter_avast:
ParentImage|startswith:
- C:\Program Files\Avast Software\
- C:\Program Files (x86)\Avast Software\
filter_google_update:
ParentImage|startswith:
- C:\Program Files\Google\Update\
- C:\Program Files (x86)\Google\Update\
condition: 1 of selection_image_* and selection_user and not 1 of filter_*
falsepositives:
- System administrator usage
- Anti virus products
- WindowsApps located in "C:\Program Files\WindowsApps\"
level: medium
license: DRL-1.1
related:
- id: cd951fdc-4b2f-47f5-ba99-a33bf61e3770
type: derived
What it detects
This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.
Known false positives
- System administrator usage
- Anti virus products
- WindowsApps located in "C:\Program Files\WindowsApps\"
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.