OctopusDeploy sign their msi's using Authenticode.
Check it's a valid signature and then check the thumbprint of the signer matches OctopusDeploy's thumbprint from one of their msi's.
This might be helpful: http://stackoverflow.com/questions/7780324/check-whether-a-given-executable-is-digitally-signed-and-valid