Windows File Creation of .diagcab Packages

Alerts on newly created Windows .diagcab files that may indicate malicious packaging or exploitation.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_event
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-06-08
Updated
2026-07-31

What it detects

This rule flags file events where a newly created file has a filename ending in .diagcab, which can indicate Windows diagnostic package deployment. Attackers may use this artifact to blend into legitimate diagnostic content or stage supporting files during exploitation. Telemetry relies on Windows file creation events and the TargetFilename suffix.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.