Batch dropper UAC self-elevation and msiexec install from GitHub raw URL
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
Microsoft Sentinel (KQL)

