PowerShell Classic Compress-Archive in Temp staging directories
Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.
FreeUnreviewedSigmamediumv1
powershell-classic-compress-archive-in-temp-staging-directories-71ff406e
title: PowerShell Classic Compress-Archive in Temp staging directories
id: 2e1f3224-4ff1-46c7-9ebe-44e4602e592c
related:
- id: daf7eb81-35fd-410d-9d7a-657837e602bb
type: similar
- id: b7a3c9a3-09ea-4934-8864-6a32cacd98d9
type: similar
- id: 85a8e5ba-bd03-4bfb-bbfa-a4409a8f8b98
type: similar
- id: 71ff406e-b633-4989-96ec-bc49d825a412
type: derived
status: test
description: This rule flags PowerShell Classic executions that use the Compress-Archive cmdlet to compress content into common temporary staging locations such as $env:TEMP, AppData\Local\Temp, or \Windows\Temp. Compressing staged files can help an attacker package collected data for easier handling and reduce the size of data prepared for outbound transfer. It relies on PowerShell script command-line telemetry matching the Compress-Archive destination patterns to identify these behaviors.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1074.001/T1074.001.md
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_classic/posh_pc_susp_zip_compress.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2021-07-20
modified: 2023-12-18
tags:
- attack.collection
- attack.t1074.001
logsource:
product: windows
service: powershell-classic
detection:
selection:
Data|contains:
- Compress-Archive -Path*-DestinationPath $env:TEMP
- Compress-Archive -Path*-DestinationPath*\AppData\Local\Temp\
- Compress-Archive -Path*-DestinationPath*:\Windows\Temp\
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1
What it detects
This rule flags PowerShell Classic executions that use the Compress-Archive cmdlet to compress content into common temporary staging locations such as $env:TEMP, AppData\Local\Temp, or \Windows\Temp. Compressing staged files can help an attacker package collected data for easier handling and reduce the size of data prepared for outbound transfer. It relies on PowerShell script command-line telemetry matching the Compress-Archive destination patterns to identify these behaviors.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.