<<< Hide Navigation Hide TOC >>>
Compressed File Extraction Via Tar.EXE (bf361876-6620-407a-812f-bfe11e51e924)
Detects execution of "tar.exe" in order to extract compressed file. Adversaries may abuse various utilities in order to decompress data to avoid detection.
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Compressed File Extraction Via Tar.EXE (bf361876-6620-407a-812f-bfe11e51e924) | Sigma-Rules | Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) | Attack Pattern | 1 |
Compressed File Extraction Via Tar.EXE (bf361876-6620-407a-812f-bfe11e51e924) | Sigma-Rules | Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) | Attack Pattern | 1 |
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) | Attack Pattern | Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) | Attack Pattern | 2 |