Msiexec LOLBin Remote MSI Package Fetch via HTTP T1218.007
This rule detects the use of the 'msiexec.exe' utility to fetch and potentially execute an '.msi' installer package directly from a remote source via HTTP. This behavior is a known technique for bypassing application control by abusing a signed system binary to download and install malicious packages.
Suricata

