Lumma Stealer / Amadey Bot Injection into msiexec.exe
Detects anomalous behavior associated with msiexec.exe that aligns with activity patterns of infostealer malwares like Lumma Stealer and Amadey Bot. This includes cross-process injection from unsigned processes, spawning of msiexec.exe by LOLBins or script interpreters, suspicious outbound network connectivity, and unauthorized access to browser credential storage files.
SentinelOne

