Windows Security Event ISO Image Mount via \\Device\\CdRom

Alerts on Windows file-access events consistent with ISO mounting by activity under \\Device\\CdRom.

FreeUnreviewedSigmamediumv1
title: Windows Security Event ISO Image Mount via \\Device\\CdRom
id: 205157b8-cc15-46aa-bbac-cdddf1578dc3
status: test
description: This rule flags Windows Security auditing events when a file object under \\Device\\CdRom* is accessed, indicating an ISO image has been mounted. Attackers commonly mount ISO images to run or stage installation content during initial access. It relies on Windows Security Event ID 4663 telemetry, including ObjectServer, ObjectType, and the ObjectName path starting with \\Device\\CdRom, while excluding specific autorun/setup executables paths.
references:
  - https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/malicious-spam-campaign-uses-iso-image-files-to-deliver-lokibot-and-nanocore
  - https://www.proofpoint.com/us/blog/threat-insight/threat-actor-profile-ta2719-uses-colorful-lures-deliver-rats-local-languages
  - https://twitter.com/MsftSecIntel/status/1257324139515269121
  - https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1553.005/T1553.005.md#atomic-test-1---mount-iso-image
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_iso_mount.yml
author: Syed Hasan (@syedhasan009), Huntrule Team
date: 2021-05-29
modified: 2023-11-09
tags:
  - attack.initial-access
  - attack.t1566.001
logsource:
  product: windows
  service: security
  definition: The advanced audit policy setting "Object Access > Audit Removable Storage" must be configured for Success/Failure
detection:
  selection:
    EventID: 4663
    ObjectServer: Security
    ObjectType: File
    ObjectName|startswith: \Device\CdRom
  filter_main_generic:
    ObjectName:
      - \Device\CdRom0\autorun.ico
      - \Device\CdRom0\setup.exe
      - \Device\CdRom0\setup64.exe
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Software installation ISO files
level: medium
license: DRL-1.1
related:
  - id: 0248a7bc-8a9a-4cd8-a57e-3ae8e073a073
    type: derived

What it detects

This rule flags Windows Security auditing events when a file object under \\Device\\CdRom* is accessed, indicating an ISO image has been mounted. Attackers commonly mount ISO images to run or stage installation content during initial access. It relies on Windows Security Event ID 4663 telemetry, including ObjectServer, ObjectType, and the ObjectName path starting with \\Device\\CdRom, while excluding specific autorun/setup executables paths.

Known false positives

  • Software installation ISO files

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.