msiexec.exe running as SYSTEM spawned by a script/task host with no installer package
msiexec.exe running as SYSTEM, spawned by a script/task host, with no installer package. Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820 Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Microsoft Sentinel (KQL)

