Skip to content
Application

Application Event ID 1033: MSI product installed

Windows Installer installed the productApplication event 1033 (MsiInstaller) records an MSI package installation: product name, version, manufacturer and result, with the installing user's SID.
1033
Event ID
1033
Channel
Application
Provider
MsiInstaller
Log file
Application.evtx
Category
Software
Default logging
Logged by default

What event 1033 means

Event 1033 is written by Windows Installer at the end of a product installation performed from an MSI package. It lists the product name, version, language, the installation status (0 for success) and the manufacturer. The user SID of the account that ran the installation is in the record's System section, not in the data.

It appears alongside 11707 (installation completed successfully) or 11708 (failed), and uninstalls produce 1034 and 11724. Together they give a reliable software installation history for MSI-based products — which includes many remote management and remote access tools.

Attackers frequently install legitimate remote access software (AnyDesk, ScreenConnect, Atera, and similar) or deliver payloads as MSI packages. A 1033 for such a product, by an unexpected user or on a server, is a good lead.

When it is logged

Audit policy / configuration

Always logged to the Application log for MSI installations.

The data is a set of unnamed insertion strings; this viewer shows them joined in Data1. Installers that do not use Windows Installer (plain EXE setups) do not produce this event.

Key fields

FieldWhat it tells you
Data1Insertion strings — product name, product version, product language, installation status (0 = success) and manufacturer, e.g. LibreOffice 6.4.2.2,6.4.2.2,1033,0,The Document Foundation.

Common benign sources

  • Software deployment by IT tools (SCCM/Intune, GPO) and users installing approved software.
  • Automatic updates of MSI-based products.

What attackers do that produces it

  • Installation of remote monitoring and management or remote access tools for persistence and hands-on access.
  • Malicious MSI packages executed with msiexec from a download or network share.

Investigation tips

  • List products by install time and compare with the expected software baseline.
  • Resolve the user SID in the System section to identify who installed the product.
  • Look for the msiexec.exe command line in 4688 or Sysmon 1 and for the MSI file source.
  • Check 11707 for the matching completion record and 1034/11724 for later removal.

MITRE ATT&CK techniques

TechniqueTactics
T1218.007 System Binary Proxy Execution: MsiexecStealth
T1219 Remote Access ToolsCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading