Skip to content

Hide Navigation Hide TOC

Winrar Compressing Dump Files (1ac14d38-3dfc-4635-92c7-e3fd1c5f5bfc)

Detects execution of WinRAR in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.

Cluster A Galaxy A Cluster B Galaxy B Level
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern Winrar Compressing Dump Files (1ac14d38-3dfc-4635-92c7-e3fd1c5f5bfc) Sigma-Rules 1
Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) Attack Pattern Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern 2