PowerShell Classic Compress-Archive in Temp staging directories

Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.

FreeUnreviewedSigmamediumv1
title: PowerShell Classic Compress-Archive in Temp staging directories
id: 2e1f3224-4ff1-46c7-9ebe-44e4602e592c
related:
  - id: daf7eb81-35fd-410d-9d7a-657837e602bb
    type: similar
  - id: b7a3c9a3-09ea-4934-8864-6a32cacd98d9
    type: similar
  - id: 85a8e5ba-bd03-4bfb-bbfa-a4409a8f8b98
    type: similar
  - id: 71ff406e-b633-4989-96ec-bc49d825a412
    type: derived
status: test
description: This rule flags PowerShell Classic executions that use the Compress-Archive cmdlet to compress content into common temporary staging locations such as $env:TEMP, AppData\Local\Temp, or \Windows\Temp. Compressing staged files can help an attacker package collected data for easier handling and reduce the size of data prepared for outbound transfer. It relies on PowerShell script command-line telemetry matching the Compress-Archive destination patterns to identify these behaviors.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1074.001/T1074.001.md
  - https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_classic/posh_pc_susp_zip_compress.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2021-07-20
modified: 2023-12-18
tags:
  - attack.collection
  - attack.t1074.001
logsource:
  product: windows
  service: powershell-classic
detection:
  selection:
    Data|contains:
      - Compress-Archive -Path*-DestinationPath $env:TEMP
      - Compress-Archive -Path*-DestinationPath*\AppData\Local\Temp\
      - Compress-Archive -Path*-DestinationPath*:\Windows\Temp\
  condition: selection
falsepositives:
  - Unknown
level: medium
license: DRL-1.1

What it detects

This rule flags PowerShell Classic executions that use the Compress-Archive cmdlet to compress content into common temporary staging locations such as $env:TEMP, AppData\Local\Temp, or \Windows\Temp. Compressing staged files can help an attacker package collected data for easier handling and reduce the size of data prepared for outbound transfer. It relies on PowerShell script command-line telemetry matching the Compress-Archive destination patterns to identify these behaviors.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.