Suspicious Code Execution via InstallUtil LOLBIN (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-02
Updated
2026-09-02

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects InstallUtil.exe run with uninstall or log-suppression flags used to trigger attacker code in a .NET assembly's Uninstall method while avoiding console output, a signed-binary proxy technique. InstallUtil abuse is a defense-evasion technique tracked in the Red Canary Threat Detection Report. Detecting these command lines surfaces code execution under a trusted Microsoft utility.

Related detections2 linkedT1218.004 — drag to rearrange
Suspicious Service Persistence via InstallUtil with Masqueraded Service Name
Suspicious PowerShell Spawning .NET LOLBIN (via process_creation)
Suspicious Code Execution via InstallUtil LOLBIN (via process_creation)
Pivot detection · T1218.004 · 2 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.