LoFP LoFP / legitimate usage of \".diagcab\" files

Techniques

Sample rules

Suspicious Cabinet File Execution Via Msdt.EXE

Description

Detects execution of msdt.exe using the “cab” flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190

Detection logic

condition: all of selection_*
selection_cmd:
  CommandLine|contains|windash: ' -cab '
selection_img:
- Image|endswith: \msdt.exe
- OriginalFileName: msdt.exe