Compliance Node Overview
MITRE ATT&CK T1218.007 (Msiexec) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi). The Msiexec.exe binary may also be digitally signed by Microsoft. Adversaries may abuse msiexec.exe to launch local or network accessible MSI files. Msiexec.exe can also execute DLLs. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1218/007/
SHA-256 integrity: 37908b7608b96db9b0ad1a9658acaa98ccec6a1a6644d1b951e2344f544f44f9
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1218.007: Msiexec (https://attack.mitre.org/techniques/T1218/007/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.