Well-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques
title: Tap Installer Execution
id: 99793437-3e16-439b-be0f-078782cf953d
status: test
description: Well-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques
references:
- https://community.openvpn.net/openvpn/wiki/ManagingWindowsTAPDrivers
author: Daniil Yugoslavskiy, Ian Davis, oscd.community
date: 2019-10-24
modified: 2023-12-11
tags:
- attack.exfiltration
- attack.t1048
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\tapinstall.exe'
filter_optional_avast:
Image|contains:
- ':\Program Files\Avast Software\SecureLine VPN\'
- ':\Program Files (x86)\Avast Software\SecureLine VPN\'
filter_optional_openvpn:
Image|contains: ':\Program Files\OpenVPN Connect\drivers\tap\'
filter_optional_protonvpn:
Image|contains: ':\Program Files (x86)\Proton Technologies\ProtonVPNTap\installer\'
condition: selection and not 1 of filter_optional_*
falsepositives:
- Legitimate OpenVPN TAP installation
level: medium
imProcessCreate
| where TargetProcessName endswith "\\tapinstall.exe" and (not(((TargetProcessName contains ":\\Program Files\\Avast Software\\SecureLine VPN\\" or TargetProcessName contains ":\\Program Files (x86)\\Avast Software\\SecureLine VPN\\") or TargetProcessName contains ":\\Program Files\\OpenVPN Connect\\drivers\\tap\\" or TargetProcessName contains ":\\Program Files (x86)\\Proton Technologies\\ProtonVPNTap\\installer\\")))
| Sentinel Table | Notes |
|---|---|
imProcessCreate | Ensure this data connector is enabled |