
Rule Info
Name
Suspicious Msiexec Quiet Install From Remote Location
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects usage of Msiexec.exe to install packages hosted remotely quietly
Date
2022-10-28 00:00:00
Modified
2024-03-13 00:00:00
Id
8150732a-0c9d-4a99-82b9-9efb9b90c40c
Tags
attack.defense-evasion attack.t1218.007
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
frack113
Merge PR #4767 from @frack113 - Update additional rules to use the `windash` modifier
2024-03-15