Description
Detects network traffic carrying the Microsoft cabinet (CAB) archive signature. CAB archives package malware stages and installers, so identification supports inspection and blocking policies.
1 SID: 20461
Detects network traffic carrying the Microsoft cabinet (CAB) archive signature. CAB archives package malware stages and installers, so identification supports inspection and blocking policies.