LoFP LoFP / t1218.007

t1218.007

TitleTags
false positives depend on scripts and administrative tools used in the monitored environment
false positives may be present, filter by destination or parent process as needed.
false positives will be present and filtering is required.
false positives will be present with msiexec spawning cmd or powershell. filtering will be needed. in addition, add other known discovery processes to enhance query.
false positives will only be present if the msiexec process legitimately spawns windbg. filter as needed.
legitimate script
other possible 3rd party msi software installers use this technique as part of its installation process.
some rare installers were seen communicating with external servers for additional information. while its a very rare occurrence in some environments an initial baseline might be required.
this analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. filter as needed.
windowsapps installing updates via the quiet flag