Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443

Alerts when msiexec.exe starts outbound connections to ports 80 or 443, indicating potential remote package retrieval.

FreeReviewedSigma · Low · v5
Product
windows
Category
network_connection
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-01-16
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies outbound network connections initiated by a Msiexec.exe process to destinations using TCP port 80 or 443. Adversaries may abuse Msiexec.exe to retrieve and execute remotely hosted installation packages, making unexpected web traffic from this binary noteworthy. Telemetry required includes Windows network connection events with the initiating process image name and destination port.

Related detections9 linkedT1218.007 — drag to rearrange
Malicious Msiexec Execution of Staged Update Package via Process Creation
Msiexec Spawning Batch Script Child Process
Possible PurpleFox MSHTA to Msiexec Remote MSI Chain
Malicious Remote MSI Execution with Image Extension via msiexec (via process_creation)
Suspicious Raspberry Robin Msiexec Spawning a Proxy Binary (via process_creation)
Malicious Msiexec Installation of a Remote MSI Package (via process_creation)
Suspicious msiexec Remote Package Installation over HTTP
Malicious MSI Installation from Remote WebDAV Share via process_creation
Suspicious Msiexec Remote Package Installation from URL via Process Creation
Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443
Pivot detection · T1218.007 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.