Skip to content
Application

Application Event ID 11707: MSI installation succeeded

Product: <name> -- Installation completed successfullyApplication event 11707 (MsiInstaller) confirms that an MSI product installation completed successfully, with the product name and the installing user's SID.
11707
Event ID
11707
Channel
Application
Provider
MsiInstaller
Log file
Application.evtx
Category
Software
Default logging
Logged by default

What event 11707 means

Event 11707 is written by Windows Installer when an installation finishes successfully. The message is short — Product: <name> -- Installation completed successfully. — and the account that ran it is identified by the user SID in the record's System section. Failed installations are logged as 11708.

It is usually paired with 1033, which adds version and manufacturer. Uninstalls appear as 11724 and 1034. Because both install events are written by default and survive for as long as the Application log retains them, they are a practical source for a software installation timeline.

In incident response, 11707 is most useful to date the arrival of remote access tools, attacker utilities packaged as MSI, or unexpected software on servers.

When it is logged

Audit policy / configuration

Always logged to the Application log for successful MSI installations.

The data is a set of unnamed insertion strings; this viewer shows them joined in Data1.

Key fields

FieldWhat it tells you
Data1The message text, e.g. Product: Google Update Helper -- Installation completed successfully.

Common benign sources

  • Software deployment, updates and user-initiated installs of MSI packages.

What attackers do that produces it

  • Installation of remote access software or malicious MSI payloads by an intruder.

Investigation tips

  • Extract the product name and timestamp; compare with approved software and with the incident timeline.
  • Resolve the user SID to find the installing account and check its logons (4624) around that time.
  • Find the msiexec.exe process and parent in 4688 or Sysmon 1.

MITRE ATT&CK techniques

TechniqueTactics
T1218.007 System Binary Proxy Execution: MsiexecStealth
T1219 Remote Access ToolsCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading