{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/installer-abuse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["windows","persistence","living-off-the-land","installer-abuse"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently abuse the Windows Installer process (msiexec.exe) as a living-off-the-land technique to maintain persistence on compromised Windows systems. By leveraging the legitimate functionality of msiexec.exe, attackers can mask the creation of malicious scheduled tasks, the placement of payloads in startup directories, or the modification of Windows Registry Run keys. Because msiexec.exe is a trusted system binary, its involvement in these actions often bypasses basic security scrutiny. Defenders should monitor for instances where msiexec.exe performs actions inconsistent with standard software installation patterns, such as creating persistence entries in non-standard locations or modifying registry keys outside of defined enterprise software deployment windows.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker delivers a malicious MSI package or executes an msiexec.exe command line via a compromised vector.\u003c/li\u003e\n\u003cli\u003eMsiexec.exe is executed with elevated privileges (often via UAC bypass or service account impersonation).\u003c/li\u003e\n\u003cli\u003eThe installer process proceeds to write a malicious binary or script to a persistence location, such as the Startup folder.\u003c/li\u003e\n\u003cli\u003eAlternatively, msiexec.exe modifies registry keys under HKLM or HKCU CurrentVersion\\Run to trigger execution at next login.\u003c/li\u003e\n\u003cli\u003eThe installer process may create a new Scheduled Task to ensure persistent background execution.\u003c/li\u003e\n\u003cli\u003eAttacker deletes the original MSI package to clean up artifacts while leaving the persistence mechanism intact.\u003c/li\u003e\n\u003cli\u003eUpon system reboot or user login, the established persistence entry invokes the malicious payload to regain access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an adversary to maintain long-term, persistent access to a compromised host, facilitating further lateral movement, credential theft, or exfiltration. Because this technique uses a native Windows component, it allows for stealthy execution that may evade signature-based detection mechanisms that ignore trusted system binaries.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the implementation of EDR telemetry that tracks file and registry modifications specifically sourced from the msiexec.exe process. Enable the provided Sigma rules to capture these modifications. Maintain an allowlist of legitimate installer behaviors, specifically focusing on enterprise-managed deployment software and trusted update processes, to reduce false positives. Investigate any instances where msiexec.exe is spawned by non-standard parent processes, such as web servers, unauthorized PowerShell scripts, or unexpected user-level processes.\u003c/p\u003e\n","date_modified":"2026-10-05T12:02:44Z","date_published":"2026-10-05T12:02:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-msiexec-persistence/","summary":"This brief identifies the abuse of the Windows Installer process, msiexec.exe, by adversaries to establish persistence via scheduled tasks, startup folders, and registry autorun keys.","title":"Detection of Msiexec.exe Used for Persistence","url":"https://feed.craftedsignal.io/briefs/2026-10-msiexec-persistence/"}],"language":"en","title":"CraftedSignal Threat Feed - Installer-Abuse","version":"https://jsonfeed.org/version/1.1"}