Skip to content

<<< Hide Navigation Hide TOC >>>

Compressed File Extraction Via Tar.EXE (bf361876-6620-407a-812f-bfe11e51e924)

Detects execution of "tar.exe" in order to extract compressed file. Adversaries may abuse various utilities in order to decompress data to avoid detection.

Galaxy ColorsSigma-Rule...Attack Pat...
Rows: 3
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
Compressed File Extraction Via Tar.EXE (bf361876-6620-407a-812f-bfe11e51e924) Sigma-Rules Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern 1
Compressed File Extraction Via Tar.EXE (bf361876-6620-407a-812f-bfe11e51e924) Sigma-Rules Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) Attack Pattern 1
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) Attack Pattern Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) Attack Pattern 2