Detect Elevated Windows Installer (msiexec) Running as SYSTEM

Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community (SigmaHQ), DRL 1.1
Published
2020-10-13
Updated
2026-07-30
title: Detect Elevated Windows Installer (msiexec) Running as SYSTEM
id: 80a002b7-a092-4358-94e6-98e25850d695
status: test
description: This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.
references:
  - https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-48-638.jpg
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_always_install_elevated_windows_installer.yml
author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule Team
date: 2020-10-13
modified: 2024-12-01
tags:
  - attack.privilege-escalation
  - attack.t1548.002
logsource:
  product: windows
  category: process_creation
detection:
  selection_user:
    User|contains:
      - AUTHORI
      - AUTORI
  selection_image_1:
    Image|contains|all:
      - \Windows\Installer\
      - msi
    Image|endswith: tmp
  selection_image_2:
    Image|endswith: \msiexec.exe
    IntegrityLevel:
      - System
      - S-1-16-16384
  filter_installer:
    ParentImage: C:\Windows\System32\services.exe
  filter_repair:
    - CommandLine|endswith: \system32\msiexec.exe /V
    - ParentCommandLine|endswith: \system32\msiexec.exe /V
  filter_sophos:
    ParentImage|startswith: C:\ProgramData\Sophos\
  filter_avira:
    ParentImage|startswith: C:\ProgramData\Avira\
  filter_avast:
    ParentImage|startswith:
      - C:\Program Files\Avast Software\
      - C:\Program Files (x86)\Avast Software\
  filter_google_update:
    ParentImage|startswith:
      - C:\Program Files\Google\Update\
      - C:\Program Files (x86)\Google\Update\
  condition: 1 of selection_image_* and selection_user and not 1 of filter_*
falsepositives:
  - System administrator usage
  - Anti virus products
  - WindowsApps located in "C:\Program Files\WindowsApps\"
level: medium
license: DRL-1.1
related:
  - id: cd951fdc-4b2f-47f5-ba99-a33bf61e3770
    type: derived