Windows Process Creation: IExpress.exe Creating Self-Extracting Packages
Identifies IExpress.exe usage to generate self-extracting packages, including makecab.exe involvement and IExpress command-line patterns.
- Product
- windows
- Category
- process_creation
- Author
- Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2024-02-05
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows executions where iexpress.exe is used to create self-extracting packages, based on process relationships and specific command-line patterns. Attackers may leverage iexpress to compile or package content for execution, making it important to review the exact invocation parameters and any referenced build files. It relies on process creation telemetry, including parent image, process image/original filename, and the iexpress command line (notably the presence of ' /n ').
Reporting behind it
- strontic.github.iohttps://strontic.github.io/xcyclopedia/library/iexpress.exe-D594B2A33EFAFD0EABF09E3FDC05FCEA.html
- en.wikipedia.orghttps://en.wikipedia.org/wiki/IExpress
- decoded.avast.iohttps://decoded.avast.io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/
- virustotal.comhttps://www.virustotal.com/gui/file/602f4ae507fa8de57ada079adff25a6c2a899bd25cd092d0af7e62cdb619c93c/behavior
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_iexpress_execution.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: IExpress.exe Creating Self-Extracting Packages"
id: 76762cfb-1d99-43ae-b969-c6e040bd3791
status: test
description: This rule identifies Windows executions where iexpress.exe is used to create self-extracting packages, based on process relationships and specific command-line patterns. Attackers may leverage iexpress to compile or package content for execution, making it important to review the exact invocation parameters and any referenced build files. It relies on process creation telemetry, including parent image, process image/original filename, and the iexpress command line (notably the presence of ' /n ').
references:
- https://strontic.github.io/xcyclopedia/library/iexpress.exe-D594B2A33EFAFD0EABF09E3FDC05FCEA.html
- https://en.wikipedia.org/wiki/IExpress
- https://decoded.avast.io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/
- https://www.virustotal.com/gui/file/602f4ae507fa8de57ada079adff25a6c2a899bd25cd092d0af7e62cdb619c93c/behavior
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_iexpress_execution.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2024-02-05
tags:
- attack.stealth
- attack.t1218
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection_1_parent:
ParentImage|endswith: \iexpress.exe
selection_1_img:
- Image|endswith: \makecab.exe
- OriginalFileName: makecab.exe
selection_2_img:
- Image|endswith: \iexpress.exe
- OriginalFileName: IEXPRESS.exe
selection_2_cli:
CommandLine|contains: " /n "
condition: all of selection_1_* or all of selection_2_*
falsepositives:
- Administrators building packages using iexpress.exe
level: medium
license: DRL-1.1
related:
- id: c2b478fc-09bf-40b2-8768-ab3ec8d61c9a
type: derived