Msiexec
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi).(Citation: Microsoft msiexec) The Msiexec.exe binary may also be digitally signed by Microsoft. Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs.(Citation: LOLBAS Msiexec)(Citation: TrendMicro Msiexec Feb 2018) Si...
BY SOURCE
PROCEDURES (23)
Auto-extracted: 4 detections for process creation monitoring
Auto-extracted: 2 detections for download
Auto-extracted: 2 detections for startup
Auto-extracted: 2 detections for privilege
Auto-extracted: 2 detections for suspicious
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for child process
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for network connection monitoring
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for http
Auto-extracted: 1 detections for parent process
Auto-extracted: 1 detections for unusual
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for remote
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for bypass