PowerShell Compress-Archive Cmdlet Execution for Data Compression

Flags PowerShell scripts using the Compress-Archive cmdlet, consistent with local data packaging before collection or exfiltration.

FreeReviewedSigma · Low · v5
Product
windows
Category
ps_script
Author
Timur Zinniatullin, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-21
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies PowerShell script block content that includes the Compress-Archive cmdlet, indicating automated compression of files or folders. Adversaries may compress collected or sensitive data to reduce size and improve portability ahead of exfiltration. The detection relies on Script Block Logging telemetry capturing PowerShell script text that contains the cmdlet name.

Related detections2 linkedT1560 — drag to rearrange
Windows tar.exe Used to Create Compressed Archives
Windows: tar.exe Archive Extraction Using -x Flag
PowerShell Compress-Archive Cmdlet Execution for Data Compression
Pivot detection · T1560 · 2 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.