Windows tar.exe Used to Create Compressed Archives

Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), AdmU3 (SigmaHQ), DRL 1.1
Published
2023-12-19
Updated
2026-07-30

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions where Windows tar.exe (or bsdtar with OriginalFileName) is invoked to create or update an archive. Adversaries can use standard compression utilities to package data prior to staging or exfiltration, reducing size and potentially blending in with legitimate archiving activity. It relies on Windows process creation telemetry, specifically the executable path/name and the presence of tar options (-c, -r, -u) in the command line.

Related detections9 linkedT1560.001 — drag to rearrange
Windows: tar.exe Archive Extraction Using -x Flag
Data Collection via Rar Archiving With Recursion and Compression Flags
Suspicious Archiving of Registry Hives via WinRAR (UAT-8099)
Suspicious Data Staging via Password-Protected Archive Utility (via process_creation)
Suspicious Archive Staged in Web Accessible Directory via tar
Suspicious Archive Staged in Web Root via tar on Ivanti EPMM
Suspicious Payload Staging in Public Libraries Directory via file_event
Suspicious macOS Data Staging via ditto to Temp Archive in Attacker Directory (via process_creation)
Suspicious WinRAR Silent Archive Staging
Windows tar.exe Used to Create Compressed Archives
Pivot detection · T1560.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.