title: Tap Installer Execution ruletype: Sigma author: Daniil Yugoslavskiy, Ian Davis, oscd.community date: 2019/10/24 description: Well-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques detection: SELECTION_1: EventID: 1 SELECTION_2: Image: '*\tapinstall.exe' condition: (SELECTION_1 and SELECTION_2) falsepositives: - Legitimate OpenVPN TAP insntallation id: 99793437-3e16-439b-be0f-078782cf953d level: medium logsource: category: process_creation product: windows modified: 2021/11/27 status: test tags: - attack.exfiltration - attack.t1048