Detect Elevated Windows Installer (msiexec) Running as SYSTEM
Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.
- Product
- windows
- Category
- process_creation
- Author
- Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-10-13
- Updated
- 2026-07-30
ATT&CK techniques
Priv Esc → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.
Reporting behind it
- image.slidesharecdn.comhttps://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-48-638.jpg
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_always_install_elevated_windows_installer.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Detect Elevated Windows Installer (msiexec) Running as SYSTEM
id: 80a002b7-a092-4358-94e6-98e25850d695
status: test
description: This rule identifies Windows Installer processes (msiexec.exe) launching MSI-related activity from the Windows Installer directory and running with SYSTEM integrity (including the S-1-16-16384 marker). It matters because installing or repairing software under SYSTEM context can be abused to gain or maintain elevated privileges. The detection relies on process creation telemetry, including process image path, integrity level, parent process and command line patterns, and exclusions for common benign installer/repair and security product parents.
references:
- https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-48-638.jpg
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_always_install_elevated_windows_installer.yml
author: Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule Team
date: 2020-10-13
modified: 2024-12-01
tags:
- attack.privilege-escalation
- attack.t1548.002
logsource:
product: windows
category: process_creation
detection:
selection_user:
User|contains:
- AUTHORI
- AUTORI
selection_image_1:
Image|contains|all:
- \Windows\Installer\
- msi
Image|endswith: tmp
selection_image_2:
Image|endswith: \msiexec.exe
IntegrityLevel:
- System
- S-1-16-16384
filter_installer:
ParentImage: C:\Windows\System32\services.exe
filter_repair:
- CommandLine|endswith: \system32\msiexec.exe /V
- ParentCommandLine|endswith: \system32\msiexec.exe /V
filter_sophos:
ParentImage|startswith: C:\ProgramData\Sophos\
filter_avira:
ParentImage|startswith: C:\ProgramData\Avira\
filter_avast:
ParentImage|startswith:
- C:\Program Files\Avast Software\
- C:\Program Files (x86)\Avast Software\
filter_google_update:
ParentImage|startswith:
- C:\Program Files\Google\Update\
- C:\Program Files (x86)\Google\Update\
condition: 1 of selection_image_* and selection_user and not 1 of filter_*
falsepositives:
- System administrator usage
- Anti virus products
- WindowsApps located in "C:\Program Files\WindowsApps\"
level: medium
license: DRL-1.1
related:
- id: cd951fdc-4b2f-47f5-ba99-a33bf61e3770
type: derived