makecab.exe

by Microsoft
System UtilityLOLBinmedium risk

Summary

Windows Cabinet File creation utility - compresses files into .cab archives. Signed Microsoft binary that can be abused for data staging.

makecab.exe is the 542nd most commonly executed Windows program in EchoTrail's dataset, observed 9,816 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by TiWorker.exe.

542nd
most commonly executed Windows program
9,816
observed executions
low
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3299.95%
  • C:\Windows\winsxs\amd64_microsoft-windows-makecab_31bf3856ad364e35_6.1.7600.16385_none_4cc4738d82efdf850.04%
  • C:\Windows\SysWOW640.01%

Top Hashes (SHA256)

  • f9ebaa95c93aa8ce217a4ad8715ccf2b7a3fc7a951da44b78a9bb2c53b9bcace24.85%
  • ba31ad8eca19c5fe03f6a5c64c8e0adfc7bd8d04b1f4e1c11d167467fd5261e920.15%
  • 6992e53ab2d927d6131142e328ba5d6d985c2a7eb64dc5cea4d8980dcf03e76815.95%
  • 8fab793da23798edbcce3c3ca73e8b62587ed6fcba28b73076ade3f610580bc18.25%
  • 925b31c2516090f291e78dbd285173a32f0d70bee5efabfa4e1145b9f85465638.17%
  • c55818c51e4a42dd2f9194ce754596a23f1ec3186092b1546b2409b1b3577c7e7.97%
  • 68b25a55eeafddc00e2b9aa52be0e7ab36cfc96f8c8de82ddf2ce888e557f08b3.05%
  • 59a1045b66ba8b8435df20c72b9c3aadcffb0553d98d0f0f46529589b9001a122.54%
  • 10a7e57d7ca6c9c41b2bb4c32a892e5d79b23a46ebd9f5d9f7e8c683e7bbd3c52.28%
  • 12d1e818c64d02f48c0a8a1094390329b8a65248e53e43d21ccf94e9a97015561.69%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does makecab.exe normally do?

Used by Windows Update, driver packaging, and SCCM for cabinet file creation. Common in software packaging workflows.

When is makecab.exe suspicious?

Compressing user data directories. Creating cab files in temp or staging directories. Execution by non-admin users on endpoints that do not perform software packaging.

How do attackers abuse makecab.exe?

Attackers use makecab to compress data before exfiltration. As a signed Microsoft binary, it bypasses application whitelisting. Can also be used to encode/decode files using the cabinet format.

Detection guidance

Monitor for makecab targeting sensitive directories. Alert on cabinet creation in unusual locations. Correlate with subsequent network transfer activity.

False positive notes

Windows Update, SCCM, and software packaging tools commonly use makecab.

MITRE ATT&CK techniques

References

Related Processes

expand.exeextrac32.exe

Ask Rocky about makecab.exe

Rocky answers questions about makecab.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.