{"id":"T1218.004","name":"InstallUtil","url":"https://attack.mitre.org/techniques/T1218/004","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0138","stix_id":"x-mitre-detection-strategy--7f7679d8-c2eb-4fcc-be46-27055ef491a6","name":"Detection of Malicious Code Execution via InstallUtil.exe","url":"https://attack.mitre.org/detectionstrategies/DET0138","analytics":[{"id":"AN0388","stix_id":"x-mitre-analytic--f3478623-5b5c-482e-96f1-6b225ff8fa70","name":"Analytic 0388","description":"Execution of InstallUtil.exe from .NET framework directories with arguments specifying non-standard or attacker-supplied assemblies, especially when followed by suspicious child process creation or script execution. Detection also includes correlation of newly created binaries prior to InstallUtil invocation and anomalous command-line usage compared to historical baselines.","url":"https://attack.mitre.org/detectionstrategies/DET0138#AN0388","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"InstallUtilPathRegex","description":"Regex pattern for InstallUtil.exe in .NET directories; tune to exclude known good administrative scripts"},{"field":"AssemblyPathRegex","description":"Patterns for identifying suspicious assemblies (e.g., in temp folders, user profiles)"},{"field":"ChildProcessList","description":"List of suspicious child processes spawned from InstallUtil.exe (e.g., cmd.exe, powershell.exe, rundll32.exe)"},{"field":"TimeWindow","description":"Time correlation window between file creation of assembly and its execution via InstallUtil.exe"}],"live":true,"detection_strategies":["DET0138"],"techniques":["T1218.004"]}],"live":true,"version":"1.0","techniques":["T1218.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}