Detection rules › Splunk
MSIExec Install MSI File (Windows Event Log)
The Windows Installer technology uses Msiexec.exe for installing MSI and MSP packages. This tool gives you full control over the installation process
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| MsiInstaller | Event ID 1040: Beginning a Windows Installer transaction: %0 |
Rule body
id: '1117.1196'
title: MSIExec Install MSI File
description: 'The Windows Installer technology uses Msiexec.exe for installing MSI
and MSP packages. This tool gives you full control over the installation process.
-- Threat Actor Association: APT-K-47/Mysterious Elephant, APT36, TA505 -- Software
Association: Clop, DirtyMoe, Hive, MirrorBlast, Qakbot/Qbot, Yellow Cockatoo/Jupiter
Infostealer, Zloader -- LOLBAS -- Atomics T1218.007 Test #1 Atomics T1218.007 Test
#2 Atomics T1218.007 Test #3 Atomics T1218.007 Test #4'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=1040) OR
"<EventID>1040<") TERM(MsiInstaller) OR TERM(ingress.event.procstart) | rex field=Message
"(?i)Beginning\sa\sWindows\sInstaller\stransaction:(\s+)?(?<process>.+)" | table
_time, host, user host, signature_id, user, process | bin span=1s | stats values(*)
as * by _time, host | eventstats dc(process) as c_process by process | where c_process
< 2 and isnotnull(process) '
techniques:
- defense-evasion:system binary proxy execution:msiexec
technique_id:
- T1218.007
data_category:
- Windows event logs
references:
- https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=1040) OR "<EventID>1040<") TERM(MsiInstaller) OR TERM(ingress.event.procstart)
Stage 2: rex
| rex field=Message "(?i)Beginning\sa\sWindows\sInstaller\stransaction:(\s+)?(?<process>.+)"
Stage 3: table
| table _time, host, user host, signature_id, user, process
Stage 4: bucket
| bin span=1s
Stage 5: stats
| stats values(*) as * by _time, host
Stage 6: eventstats
| eventstats dc(process) as c_process by process
Stage 7: where
| where c_process < 2 and isnotnull(process)
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq value:"1040" |
c_process | lt |
| field:"c_process" kind:lt value:"2" |
process | is_not_null | field:"CommandLine" kind:is_not_null |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>1040<" |
| 1 | MsiInstaller |
| 1 | ingress.event.procstart |