Potentially Suspicious Cabinet File Expansion
Description
Detects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
Query · sigma
selection_cmd: Image|endswith: \expand.exe CommandLine|contains|windash: '-F:' selection_folders_1: CommandLine|contains: - :\Perflogs\ - :\ProgramData - :\Users\Public\ - :\Windows\Temp\ - \Admin$\ - \AppData\Local\Temp\ - \AppData\Roaming\ - \C$\ - \Temporary Internet selection_folders_2: - CommandLine|contains|all: - :\Users\ - \Favorites\ - CommandLine|contains|all: - :\Users\ - \Favourites\ - CommandLine|contains|all: - :\Users\ - \Contacts\ filter_optional_dell: ParentImage: C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe CommandLine|contains: C:\ProgramData\Dell\UpdateService\Temp\ condition: selection_cmd and 1 of selection_folders_* and not 1 of filter_optional_*
Known false positives
- System administrator Usage