<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Installer-Abuse - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/installer-abuse/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:02:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/installer-abuse/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Msiexec.exe Used for Persistence</title><link>https://feed.craftedsignal.io/briefs/2026-10-msiexec-persistence/</link><pubDate>Mon, 05 Oct 2026 12:02:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-msiexec-persistence/</guid><description>This brief identifies the abuse of the Windows Installer process, msiexec.exe, by adversaries to establish persistence via scheduled tasks, startup folders, and registry autorun keys.</description><content:encoded><![CDATA[<p>Adversaries frequently abuse the Windows Installer process (msiexec.exe) as a living-off-the-land technique to maintain persistence on compromised Windows systems. By leveraging the legitimate functionality of msiexec.exe, attackers can mask the creation of malicious scheduled tasks, the placement of payloads in startup directories, or the modification of Windows Registry Run keys. Because msiexec.exe is a trusted system binary, its involvement in these actions often bypasses basic security scrutiny. Defenders should monitor for instances where msiexec.exe performs actions inconsistent with standard software installation patterns, such as creating persistence entries in non-standard locations or modifying registry keys outside of defined enterprise software deployment windows.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker delivers a malicious MSI package or executes an msiexec.exe command line via a compromised vector.</li>
<li>Msiexec.exe is executed with elevated privileges (often via UAC bypass or service account impersonation).</li>
<li>The installer process proceeds to write a malicious binary or script to a persistence location, such as the Startup folder.</li>
<li>Alternatively, msiexec.exe modifies registry keys under HKLM or HKCU CurrentVersion\Run to trigger execution at next login.</li>
<li>The installer process may create a new Scheduled Task to ensure persistent background execution.</li>
<li>Attacker deletes the original MSI package to clean up artifacts while leaving the persistence mechanism intact.</li>
<li>Upon system reboot or user login, the established persistence entry invokes the malicious payload to regain access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an adversary to maintain long-term, persistent access to a compromised host, facilitating further lateral movement, credential theft, or exfiltration. Because this technique uses a native Windows component, it allows for stealthy execution that may evade signature-based detection mechanisms that ignore trusted system binaries.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the implementation of EDR telemetry that tracks file and registry modifications specifically sourced from the msiexec.exe process. Enable the provided Sigma rules to capture these modifications. Maintain an allowlist of legitimate installer behaviors, specifically focusing on enterprise-managed deployment software and trusted update processes, to reduce false positives. Investigate any instances where msiexec.exe is spawned by non-standard parent processes, such as web servers, unauthorized PowerShell scripts, or unexpected user-level processes.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>windows</category><category>persistence</category><category>living-off-the-land</category><category>installer-abuse</category></item></channel></rss>