Suspicious Remote MSI Install of Dokan Driver via msiexec

PremiumReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-28
Updated
2026-09-28

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects msiexec installing a Dokan filesystem package, the driver this threat actor deployed to mount a virtual drive for credential and data staging. Dokan has legitimate uses in some software, so this pattern is a low-confidence signal best correlated with subsequent dokanctl mounting and LSASS access.

Related detections9 linkedT1218.007 — drag to rearrange
Malicious Remote MSI Install of RuntimeBroker via msiexec
Suspicious Remote MSI Installation via msiexec from HTTP URL
Suspicious Msiexec Remote MSI Installation via Command Line
Malicious ScreenConnect Client Installation via Msiexec (via process_creation)
Suspicious Remote MSI Installation of RMM Tooling via Msiexec (via process_creation)
Possible DCOM MSI Install Server Execution via Msiexec Embedding (via process_creation)
Malicious Msiexec Execution of Staged Update Package via Process Creation
Msiexec Spawning Batch Script Child Process
Possible PurpleFox MSHTA to Msiexec Remote MSI Chain
Suspicious Remote MSI Install of Dokan Driver via msiexec
Pivot detection · T1218.007 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.