Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)

Alerts when WinRAR/7-Zip/PeaZIP spawns ISO image tools, a pattern consistent with archive-delivered ISO payloads.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-06-07
Updated
2026-07-30

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags Windows process executions where an archiver-related parent process (WinRAR, 7-Zip, or PeaZIP) launches an ISO-related image tool (e.g., isoburn, PowerISO, ImgBurn). Such behavior can indicate an attempt to present a malicious ISO packaged in an archive, leveraging common archiving workflows to reach an image handling application. Telemetry relies on process creation events, matching parent executable paths and child executable names by suffix.

Related detections9 linkedT1566 — drag to rearrange
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Proxy WebDAV MiniRedir Drives Execution from External Shares
Windows WebDAV Temporary File Creation with Suspicious Extensions
Okta FastPass blocks phishing authentication attempts via MFA
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)
Pivot detection · T1566 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.