Suspicious Msiexec Remote MSI Installation via Command Line

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-20
Updated
2026-09-20

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects msiexec installing an MSI package directly from a remote HTTP or HTTPS URL in silent mode. Fake browser update campaigns delivering LummaC, Amadey and PrivateLoader abuse this proxy-execution technique to fetch and run installers. Detecting remote silent installs surfaces the initial delivery stage.

Related detections9 linkedT1218.007 — drag to rearrange
Malicious ScreenConnect Client Installation via Msiexec (via process_creation)
Suspicious Remote MSI Installation of RMM Tooling via Msiexec (via process_creation)
Possible DCOM MSI Install Server Execution via Msiexec Embedding (via process_creation)
Malicious Msiexec Execution of Staged Update Package via Process Creation
Msiexec Spawning Batch Script Child Process
Possible PurpleFox MSHTA to Msiexec Remote MSI Chain
Malicious Remote MSI Execution with Image Extension via msiexec (via process_creation)
Suspicious Raspberry Robin Msiexec Spawning a Proxy Binary (via process_creation)
Malicious Msiexec Installation of a Remote MSI Package (via process_creation)
Suspicious Msiexec Remote MSI Installation via Command Line
Pivot detection · T1218.007 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.