Application Event ID 11707: MSI installation succeeded
- Event ID
- 11707
- Channel
- Application
- Provider
- MsiInstaller
- Log file
- Application.evtx
- Category
- Software
- Default logging
- Logged by default
What event 11707 means
Event 11707 is written by Windows Installer when an installation finishes successfully. The message is short — Product: <name> -- Installation completed successfully. — and the account that ran it is identified by the user SID in the record's System section. Failed installations are logged as 11708.
It is usually paired with 1033, which adds version and manufacturer. Uninstalls appear as 11724 and 1034. Because both install events are written by default and survive for as long as the Application log retains them, they are a practical source for a software installation timeline.
In incident response, 11707 is most useful to date the arrival of remote access tools, attacker utilities packaged as MSI, or unexpected software on servers.
When it is logged
Always logged to the Application log for successful MSI installations.
The data is a set of unnamed insertion strings; this viewer shows them joined in Data1.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | The message text, e.g. Product: Google Update Helper -- Installation completed successfully. |
Common benign sources
- Software deployment, updates and user-initiated installs of MSI packages.
What attackers do that produces it
- Installation of remote access software or malicious MSI payloads by an intruder.
Investigation tips
- Extract the product name and timestamp; compare with approved software and with the incident timeline.
- Resolve the user SID to find the installing account and check its logons (4624) around that time.
- Find the
msiexec.exeprocess and parent in 4688 or Sysmon 1.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.