PowerShell Compress-Archive Staging in Windows Temp or AppData Local Temp
Alerts on PowerShell Compress-Archive output written to common temp staging directories.
FreeUnreviewedSigmamediumv1
powershell-compress-archive-staging-in-windows-temp-or-appdata-local-temp-daf7eb81
title: PowerShell Compress-Archive Staging in Windows Temp or AppData Local Temp
id: 6c8a2484-b8d6-4783-b368-432415d4560a
related:
- id: 71ff406e-b633-4989-96ec-bc49d825a412
type: similar
- id: b7a3c9a3-09ea-4934-8864-6a32cacd98d9
type: similar
- id: 85a8e5ba-bd03-4bfb-bbfa-a4409a8f8b98
type: similar
- id: daf7eb81-35fd-410d-9d7a-657837e602bb
type: derived
status: test
description: This rule flags PowerShell module usage of the Compress-Archive cmdlet where the DestinationPath targets common staging areas such as %TEMP%, %AppData%\Local\Temp, or \Windows\Temp. Compressing data into temporary locations can help an attacker package collected files for later exfiltration while blending into normal system activity. It relies on Windows PowerShell module telemetry capturing the cmdlet invocation and its DestinationPath values.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1074.001/T1074.001.md
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_module/posh_pm_susp_zip_compress.yml
author: Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule Team
date: 2021-07-20
modified: 2023-12-18
tags:
- attack.collection
- attack.t1074.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection:
ContextInfo|contains|all:
- Compress-Archive -Path*-DestinationPath $env:TEMP
- Compress-Archive -Path*-DestinationPath*\AppData\Local\Temp\
- Compress-Archive -Path*-DestinationPath*:\Windows\Temp\
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1
What it detects
This rule flags PowerShell module usage of the Compress-Archive cmdlet where the DestinationPath targets common staging areas such as %TEMP%, %AppData%\Local\Temp, or \Windows\Temp. Compressing data into temporary locations can help an attacker package collected files for later exfiltration while blending into normal system activity. It relies on Windows PowerShell module telemetry capturing the cmdlet invocation and its DestinationPath values.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.