Application Event ID 1033: MSI product installed
- Event ID
- 1033
- Channel
- Application
- Provider
- MsiInstaller
- Log file
- Application.evtx
- Category
- Software
- Default logging
- Logged by default
What event 1033 means
Event 1033 is written by Windows Installer at the end of a product installation performed from an MSI package. It lists the product name, version, language, the installation status (0 for success) and the manufacturer. The user SID of the account that ran the installation is in the record's System section, not in the data.
It appears alongside 11707 (installation completed successfully) or 11708 (failed), and uninstalls produce 1034 and 11724. Together they give a reliable software installation history for MSI-based products — which includes many remote management and remote access tools.
Attackers frequently install legitimate remote access software (AnyDesk, ScreenConnect, Atera, and similar) or deliver payloads as MSI packages. A 1033 for such a product, by an unexpected user or on a server, is a good lead.
When it is logged
Always logged to the Application log for MSI installations.
The data is a set of unnamed insertion strings; this viewer shows them joined in Data1. Installers that do not use Windows Installer (plain EXE setups) do not produce this event.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Insertion strings — product name, product version, product language, installation status (0 = success) and manufacturer, e.g. LibreOffice 6.4.2.2,6.4.2.2,1033,0,The Document Foundation. |
Common benign sources
- Software deployment by IT tools (SCCM/Intune, GPO) and users installing approved software.
- Automatic updates of MSI-based products.
What attackers do that produces it
- Installation of remote monitoring and management or remote access tools for persistence and hands-on access.
- Malicious MSI packages executed with
msiexecfrom a download or network share.
Investigation tips
- List products by install time and compare with the expected software baseline.
- Resolve the user SID in the System section to identify who installed the product.
- Look for the
msiexec.execommand line in 4688 or Sysmon 1 and for the MSI file source. - Check 11707 for the matching completion record and 1034/11724 for later removal.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighAtera Agent InstallationRule by Bhabesh Raj, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.