Windows InstallUtil Execution Suspiciously Omitting /logfile Output

Alert when InstallUtil.exe runs from .NET Framework with logging parameters indicating output suppression.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-23
Updated
2026-07-31

What it detects

This rule flags process creation events where InstallUtil.exe is launched from the Microsoft .NET Framework directory while the command line contains indicators of missing or non-recorded logging. Attackers can use InstallUtil to execute payloads through a trusted binary while reducing visibility. The detection relies on Windows process creation telemetry and specific Image and CommandLine substrings/flags that match the suspicious logging configuration.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.