Possible Files Added To An Archive Via Rar.EXE (via process_creation)
This rule detects use of "rar" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration to make it portable and minimize the amount of data sent over the network.
SigmalowWindowsv1
sigma
possible-files-added-to-an-archive-via-rar-exe-via-process-creation
title: Possible Files Added To An Archive Via Rar.EXE (via process_creation)
id: c8387820-bcd8-55f4-ad05-68da4d79b94a
status: stable
description: This rule detects use of "rar" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration to make it portable and minimize the amount of data sent over the network.
references:
- https://attack.mitre.org/techniques/T1560/001/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md
- https://eqllib.readthedocs.io/en/latest/analytics/1ec33c93-3d0b-4a28-8014-dbdaae5c60ae.html
author: Huntrule Team
date: 2026-05-26
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\rar.exe'
CommandLine|contains: ' a '
condition: selection
falsepositives:
- Unknown
level: low
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.