How 7-Zip Extracts Files from MSI Installers
This article explains the technical process 7-Zip uses to unpack and extract payload files directly from Windows Installer (MSI) packages. It covers how the utility navigates the Compound File Binary Format, locates internal Cabinet (CAB) storage streams, interprets database tables to resolve file structures, and unpacks the compressed data without executing the installer itself.
The Structure of an MSI Package
To understand how 7-Zip extracts files, it helps to understand what an MSI file actually is. An MSI package is not a simple archive like a ZIP or RAR file; it is an OLE (Object Linking and Embedding) Compound File Binary Format (CFBF) document, effectively acting as a structured, filesystem-within-a-file. Inside this container resides a relational database consisting of dozens of tables that define installation logic, registry modifications, UI dialogs, and references to binary payload data.
The actual files intended for installation are generally stored
within this container as embedded or external Microsoft Cabinet
(.cab) streams.
Parsing the Compound File Container
When you open an MSI package in 7-Zip, the application uses its
built-in compound file parser rather than running the Windows Installer
engine (msiexec.exe).
- Header Identification: 7-Zip reads the signature at
the start of the file (
D0 CF 11 E0 A1 B1 1A E1) to confirm it is an OLE structured storage container. - Directory Stream Traversal: It parses the Sector Allocation Tables (SAT) and Directory entries inside the file. This reveals the virtual streams and substorages stored within the MSI database.
Locating the Embedded Payload
Once inside the compound structure, 7-Zip searches for the streams containing the actual compressed program files.
- Embedded Streams: In most self-contained MSI files,
payloads are packed into embedded cabinet streams typically named with a
leading exclamation mark (e.g.,
!_Streams/Data1.cabor simplyData1.cab). - Binary Streams: Some smaller files, custom actions,
or icons are stored directly inside the
Binarystream table.
7-Zip recognizes standard Cabinet format signatures
(MSCF) within these embedded streams and treats them as
sub-archives.
Resolving Names via Database Tables
Extracting raw CAB files often results in generic identifiers instead of real filenames. To address this, 7-Zip reads the MSI relational database tables stored in the package:
- The File Table: Maps internal file identifiers (keys) to their real target filenames and versions.
- The Directory Table: Defines the relative installation paths and reconstructed folder hierarchies.
- The Media Table: Details which cabinet stream holds which set of files (determined by sequence numbers).
By cross-referencing these tables, 7-Zip correlates the arbitrary internal stream entries with their true human-readable directory structures and filenames.
Decompressing the Cabinet Streams
After mapping the target layout, 7-Zip invokes its native CAB decompression engine:
- Algorithm Detection: 7-Zip inspects the compression flags inside the cabinet header. Microsoft Cabinet files typically use either MSZIP (a variant of Deflate) or LZX compression.
- Block Decompression: 7-Zip decodes the sequential data blocks using its internal implementations of MSZIP or LZX decoders.
- Payload Output: The uncompressed bytes are written directly to the user-specified destination folder, formatted according to the paths resolved from the database tables.
Through this sequence—reading the OLE container, parsing internal database mappings, and directly decompressing the underlying CAB streams—7-Zip safely extracts installation contents without triggering scripts, executing code, or modifying the Windows Registry.