Suspicious Silent Installation of ManageEngine Endpoint Central RMM via msiexec

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-10
Updated
2026-10-10

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects msiexec silently installing ManageEngine Endpoint Central agent software, the remote management tool abused by the WhatsApp VBScript campaign for persistent remote access. Unattended RMM deployment on endpoints that do not normally run it indicates attacker-controlled tooling. Legitimate deployments should be allowlisted.

Related detections9 linkedT1219 — drag to rearrange
Suspicious NetSupport Manager Remote Client Execution From User-Writable Path
Suspicious PowerShell Enabling OpenSSH Server With Attacker Keys via process_creation
Suspicious Curl Download to Update Executable during FortiClient EMS Exploitation
Suspicious MeshAgent Masquerading as NetworkDrivers Spawned by PowerShell
Malicious MeshCentral Agent Installation With Campaign Naming
Suspicious SimpleHelp Remote Access Tool Dropped In ProgramData Root
Suspicious MeshAgent Installation Arguments (via process_creation)
Possible AnyDesk Execution from Non-Standard Directory (via process_creation)
Suspicious MeshAgent Spawning Command Interpreter (via process_creation)
Suspicious Silent Installation of ManageEngine Endpoint Central RMM via msiexec
Pivot detection · T1219 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.