You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Native Window utilities are often employed by attackers to execute malicious code in order to abuse the elevated privileges of these processes and to blend in with normal system activity. This rule monitors for outbound TCP/UDP connections spawning from msiexec.exe as this could indicate a second-stage payload acquisition. Note that sysmon event ID 3 does not record ICMP connections.
Additional Details
Detail
Value
Type
Templated Match
Category
Defense Evasion
Apply Risk to Entities
user_username, srcDevice_hostname, srcDevice_ip
Signal Name
Network Connection from Msiexec - Sysmon
Summary Expression
Msiexec.exe made a network connection on host: {{srcDevice_hostname}}