Add file_event_win_susp_diagcab
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
title: Creation of a Diagcab
|
||||
id: 3d0ed417-3d94-4963-a562-4a92c940656a
|
||||
status: experimental
|
||||
description: Detects the creation of diagcab file
|
||||
author: frack113
|
||||
references:
|
||||
- https://threadreaderapp.com/thread/1533879688141086720.html
|
||||
date: 2022/06/08
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
detection:
|
||||
selection:
|
||||
TargetFilename|endswith: '.diagcab'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Legitimate microsoft diagcab
|
||||
level: medium
|
||||
tags:
|
||||
- attack.resource_development
|
||||
Reference in New Issue
Block a user