Detects the AlwaysInstallElevated installer policy value being set to 1 under Software/Policies/Microsoft/Windows/Installer. When enabled in both HKLM and HKCU, any user can run a crafted MSI as SYSTEM, a classic misconfiguration privilege-escalation path. The rule matched on logsource `registry_set`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields — examine the exact value in the event:
Investigation queries (read-only):
Relevant defensive analysis techniques (MITRE D3FEND), to apply where the telemetry is available:
Known benign causes for this rule:
⚠️ No automatic action. D3FEND countermeasures for a human to evaluate before any containment/hardening action:
The rule's references — CTI context to qualify the incident: