Windows WinRAR or RAR Utility Execution from Non-Default Installation Paths
Alerts on WinRAR/RAR process execution when launched from folders outside standard WinRAR installation paths.
FreeUnreviewedSigmamediumv1
windows-winrar-or-rar-utility-execution-from-non-default-installation-paths-4ede543c
title: Windows WinRAR or RAR Utility Execution from Non-Default Installation Paths
id: 6fd5265c-2222-45c2-9e71-9c556b6f32b9
status: test
description: This rule flags process creation events where the executable filename ends with WinRAR/RAR (rar.exe or winrar.exe) but the image path is not located under the typical Program Files WinRAR installation directories. Attackers may run compression utilities from unusual directories to package or stage files while blending into normal tool usage. The detection relies on Windows process creation telemetry, matching the executable name and applying path-based exclusions.
references:
- https://twitter.com/cyb3rops/status/1460978167628406785
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_winrar_uncommon_folder_execution.yml
author: Florian Roth (Nextron Systems), Tigzy, Huntrule Team
date: 2021-11-17
modified: 2025-07-16
tags:
- attack.collection
- attack.t1560.001
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith:
- \rar.exe
- \winrar.exe
- Description:
- Command line RAR
- WinRAR
filter_main_unrar:
Image|endswith: \UnRAR.exe
filter_main_path:
Image|contains:
- :\Program Files (x86)\WinRAR\
- :\Program Files\WinRAR\
filter_optional_temp:
Image|contains: :\Windows\Temp\
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Legitimate use of WinRAR in a folder of a software that bundles WinRAR
level: medium
license: DRL-1.1
related:
- id: 4ede543c-e098-43d9-a28f-dd784a13132f
type: derived
What it detects
This rule flags process creation events where the executable filename ends with WinRAR/RAR (rar.exe or winrar.exe) but the image path is not located under the typical Program Files WinRAR installation directories. Attackers may run compression utilities from unusual directories to package or stage files while blending into normal tool usage. The detection relies on Windows process creation telemetry, matching the executable name and applying path-based exclusions.
Known false positives
- Legitimate use of WinRAR in a folder of a software that bundles WinRAR
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.