| ID | Technique | Tactic |
|---|---|---|
| T1566.001 | Spearphishing Attachment | Initial Access |
Detection: Windows CAB File on Disk
Description
The following analytic detects .cab files being written to disk. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on events where the file name is '*.cab' and the action is 'write'. This activity can be significant as .cab files can be used to deliver malicious payloads, including embedded .url files that execute harmful code. If confirmed malicious, this behavior could lead to unauthorized code execution and potential system compromise. Analysts should review the file path and associated artifacts for further investigation.
Search
1
2| tstats `security_content_summariesonly`
3 count values(Filesystem.file_path) as file_path
4 min(_time) as firstTime
5 max(_time) as lastTime
6
7FROM datamodel=Endpoint.Filesystem WHERE
8
9Filesystem.action IN ("created", "modified")
10Filesystem.file_name="*.cab"
11NOT Filesystem.file_path IN (
12 "*\\AppData\\Local\\Microsoft\\*",
13 "*\\Windows Kits\\10\\ADK\\Installers\\*",
14 "C:\\Program Files (x86)\\*",
15 "C:\\Program Files\\*",
16 "C:\\ProgramData\\Microsoft\\*",
17 "C:\\ProgramData\\Package Cache\\*",
18 "C:\\Windows\\appcompat\\*",
19 "C:\\Windows\\Logs\\CBS\\*",
20 "C:\\Windows\\servicing\\*",
21 "C:\\Windows\\SoftwareDistribution\\*",
22 "C:\\Windows\\System32\\*",
23 "C:\\Windows\\SystemApps\\*",
24 "C:\\Windows\\SysWOW64\\*",
25 "C:\\Windows\\WinSxS\\*",
26)
27
28BY Filesystem.action Filesystem.dest Filesystem.file_access_time
29 Filesystem.file_create_time Filesystem.file_hash Filesystem.file_modify_time
30 Filesystem.file_name Filesystem.file_path Filesystem.file_acl
31 Filesystem.file_size Filesystem.process_guid Filesystem.process_id
32 Filesystem.user Filesystem.vendor_product
33
34
35| `drop_dm_object_name("Filesystem")`
36
37| `security_content_ctime(firstTime)`
38
39| `security_content_ctime(lastTime)`
40
41| `windows_cab_file_on_disk_filter`
Data Source
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| Sysmon EventID 11 | 'XmlWinEventLog' |
'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational' |
Macros Used
| Name | Value |
|---|---|
| security_content_summariesonly | summariesonly=summariesonly_config allow_old_summaries=oldsummaries_config fillnull_value=fillnull_config`` |
| windows_cab_file_on_disk_filter | search * |
windows_cab_file_on_disk_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
Annotations
CVE
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | 0 * * * * |
| Earliest Time | -70m@m |
| Latest Time | -10m@m |
| Schedule Window | auto |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | Yes |
Implementation
The detection is based on data that originates from Endpoint Detection and Response (EDR) agents.
These agents are designed to provide security-related telemetry from the endpoints where the agent is installed.
To implement this search, you must ingest logs that contain the process GUID, process name, and parent process.
Additionally, you must ingest complete command-line executions.
These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product.
The logs must also be mapped to the Processes node of the Endpoint data model.
Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process.
Known False Positives
Some false positives are expected from user controlled folders.
Associated Analytic Story
Intermediate Findings
| Message | Entity Field | Entity Type | Risk Score |
|---|---|---|---|
| The file [$file_path$] with a .cab extension was written to disk on endpoint $dest$. | dest | system | 20 |
Threat Objects
| Field | Type |
|---|---|
| file_path | file_path |
References
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | ✅ Passing | N/A | N/A | N/A |
| Unit | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
XmlWinEventLog |
| Integration | ✅ Passing | Dataset | XmlWinEventLog:Microsoft-Windows-Sysmon/Operational |
XmlWinEventLog |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 12