makecab.exe
Sources: 300M+ executions observed in the wild.
Summary
Windows Cabinet File creation utility - compresses files into .cab archives. Signed Microsoft binary that can be abused for data staging.
makecab.exe is the 542nd most commonly executed Windows program in EchoTrail's dataset, observed 9,816 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by TiWorker.exe.
Get this in your tools
The same record for makecab.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/makecab.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\Windows\System3299.95%
- C:\Windows\winsxs\amd64_microsoft-windows-makecab_31bf3856ad364e35_6.1.7600.16385_none_4cc4738d82efdf850.04%
- C:\Windows\SysWOW640.01%
Top Hashes (SHA256)
- f9ebaa95c93aa8ce217a4ad8715ccf2b7a3fc7a951da44b78a9bb2c53b9bcace24.85%
- ba31ad8eca19c5fe03f6a5c64c8e0adfc7bd8d04b1f4e1c11d167467fd5261e920.15%
- 6992e53ab2d927d6131142e328ba5d6d985c2a7eb64dc5cea4d8980dcf03e76815.95%
- 8fab793da23798edbcce3c3ca73e8b62587ed6fcba28b73076ade3f610580bc18.25%
- 925b31c2516090f291e78dbd285173a32f0d70bee5efabfa4e1145b9f85465638.17%
- c55818c51e4a42dd2f9194ce754596a23f1ec3186092b1546b2409b1b3577c7e7.97%
- 68b25a55eeafddc00e2b9aa52be0e7ab36cfc96f8c8de82ddf2ce888e557f08b3.05%
- 59a1045b66ba8b8435df20c72b9c3aadcffb0553d98d0f0f46529589b9001a122.54%
- 10a7e57d7ca6c9c41b2bb4c32a892e5d79b23a46ebd9f5d9f7e8c683e7bbd3c52.28%
- 12d1e818c64d02f48c0a8a1094390329b8a65248e53e43d21ccf94e9a97015561.69%
Process Ancestry
Top Grandparents
- svchost.exe95.82%
- services.exe4.03%
- explorer.exe0.09%
Top Parents
- TiWorker.exe95.96%
- TrustedInstaller.exe1.62%
- sdiagnhost.exe1.14%
- Upgrade.exe1.09%
- cmd.exe0.02%
- powershell.exe0.01%
Top Children
- conhost.exe100%
Security Analysis
What does makecab.exe normally do?
Used by Windows Update, driver packaging, and SCCM for cabinet file creation. Common in software packaging workflows.
When is makecab.exe suspicious?
Compressing user data directories. Creating cab files in temp or staging directories. Execution by non-admin users on endpoints that do not perform software packaging.
How do attackers abuse makecab.exe?
Attackers use makecab to compress data before exfiltration. As a signed Microsoft binary, it bypasses application whitelisting. Can also be used to encode/decode files using the cabinet format.
Detection guidance
Monitor for makecab targeting sensitive directories. Alert on cabinet creation in unusual locations. Correlate with subsequent network transfer activity.
False positive notes
Windows Update, SCCM, and software packaging tools commonly use makecab.
Related Processes
Ask Rocky about makecab.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for makecab.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.