makecab.exe
Summary
Windows Cabinet File creation utility - compresses files into .cab archives. Signed Microsoft binary that can be abused for data staging.
makecab.exe is the 542nd most commonly executed Windows program in EchoTrail's dataset, observed 9,816 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by TiWorker.exe.
Behavior
Top Paths
- C:\Windows\System3299.95%
- C:\Windows\winsxs\amd64_microsoft-windows-makecab_31bf3856ad364e35_6.1.7600.16385_none_4cc4738d82efdf850.04%
- C:\Windows\SysWOW640.01%
Top Hashes (SHA256)
- f9ebaa95c93aa8ce217a4ad8715ccf2b7a3fc7a951da44b78a9bb2c53b9bcace24.85%
- ba31ad8eca19c5fe03f6a5c64c8e0adfc7bd8d04b1f4e1c11d167467fd5261e920.15%
- 6992e53ab2d927d6131142e328ba5d6d985c2a7eb64dc5cea4d8980dcf03e76815.95%
- 8fab793da23798edbcce3c3ca73e8b62587ed6fcba28b73076ade3f610580bc18.25%
- 925b31c2516090f291e78dbd285173a32f0d70bee5efabfa4e1145b9f85465638.17%
- c55818c51e4a42dd2f9194ce754596a23f1ec3186092b1546b2409b1b3577c7e7.97%
- 68b25a55eeafddc00e2b9aa52be0e7ab36cfc96f8c8de82ddf2ce888e557f08b3.05%
- 59a1045b66ba8b8435df20c72b9c3aadcffb0553d98d0f0f46529589b9001a122.54%
- 10a7e57d7ca6c9c41b2bb4c32a892e5d79b23a46ebd9f5d9f7e8c683e7bbd3c52.28%
- 12d1e818c64d02f48c0a8a1094390329b8a65248e53e43d21ccf94e9a97015561.69%
Process Ancestry
Top Grandparents
- svchost.exe95.82%
- services.exe4.03%
- explorer.exe0.09%
Top Parents
- TiWorker.exe95.96%
- TrustedInstaller.exe1.62%
- sdiagnhost.exe1.14%
- Upgrade.exe1.09%
- cmd.exe0.02%
- powershell.exe0.01%
Top Children
- conhost.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does makecab.exe normally do?
Used by Windows Update, driver packaging, and SCCM for cabinet file creation. Common in software packaging workflows.
When is makecab.exe suspicious?
Compressing user data directories. Creating cab files in temp or staging directories. Execution by non-admin users on endpoints that do not perform software packaging.
How do attackers abuse makecab.exe?
Attackers use makecab to compress data before exfiltration. As a signed Microsoft binary, it bypasses application whitelisting. Can also be used to encode/decode files using the cabinet format.
Detection guidance
Monitor for makecab targeting sensitive directories. Alert on cabinet creation in unusual locations. Correlate with subsequent network transfer activity.
False positive notes
Windows Update, SCCM, and software packaging tools commonly use makecab.
Related Processes
Ask Rocky about makecab.exe
Rocky answers questions about makecab.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.