Windows Security Event ISO Image Mount via \\Device\\CdRom
Alerts on Windows file-access events consistent with ISO mounting by activity under \\Device\\CdRom.
FreeUnreviewedSigmamediumv1
windows-security-event-iso-image-mount-via-device-cdrom-0248a7bc
title: Windows Security Event ISO Image Mount via \\Device\\CdRom
id: 205157b8-cc15-46aa-bbac-cdddf1578dc3
status: test
description: This rule flags Windows Security auditing events when a file object under \\Device\\CdRom* is accessed, indicating an ISO image has been mounted. Attackers commonly mount ISO images to run or stage installation content during initial access. It relies on Windows Security Event ID 4663 telemetry, including ObjectServer, ObjectType, and the ObjectName path starting with \\Device\\CdRom, while excluding specific autorun/setup executables paths.
references:
- https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/malicious-spam-campaign-uses-iso-image-files-to-deliver-lokibot-and-nanocore
- https://www.proofpoint.com/us/blog/threat-insight/threat-actor-profile-ta2719-uses-colorful-lures-deliver-rats-local-languages
- https://twitter.com/MsftSecIntel/status/1257324139515269121
- https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1553.005/T1553.005.md#atomic-test-1---mount-iso-image
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_iso_mount.yml
author: Syed Hasan (@syedhasan009), Huntrule Team
date: 2021-05-29
modified: 2023-11-09
tags:
- attack.initial-access
- attack.t1566.001
logsource:
product: windows
service: security
definition: The advanced audit policy setting "Object Access > Audit Removable Storage" must be configured for Success/Failure
detection:
selection:
EventID: 4663
ObjectServer: Security
ObjectType: File
ObjectName|startswith: \Device\CdRom
filter_main_generic:
ObjectName:
- \Device\CdRom0\autorun.ico
- \Device\CdRom0\setup.exe
- \Device\CdRom0\setup64.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Software installation ISO files
level: medium
license: DRL-1.1
related:
- id: 0248a7bc-8a9a-4cd8-a57e-3ae8e073a073
type: derived
What it detects
This rule flags Windows Security auditing events when a file object under \\Device\\CdRom* is accessed, indicating an ISO image has been mounted. Attackers commonly mount ISO images to run or stage installation content during initial access. It relies on Windows Security Event ID 4663 telemetry, including ObjectServer, ObjectType, and the ObjectName path starting with \\Device\\CdRom, while excluding specific autorun/setup executables paths.
Known false positives
- Software installation ISO files
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.