Rar Usage with Password and Compression Level

 Original Source: [Sigma source]
Title: Rar Usage with Password and Compression Level
Status: test
Description:Detects the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level. This is pretty indicative of malicious actions.
References:
  -https://labs.sentinelone.com/the-anatomy-of-an-apt-attack-and-cobaltstrike-beacons-encoded-configuration/
  -https://ss64.com/bash/rar.html
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1560.001/T1560.001.md
Author: @ROxPinTeddy
Date: 2020-05-12
modified:2022-03-16
Tags:
  • -'attack.collection'
  • -'attack.t1560.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_password:
    CommandLine|contains: ' -hp'
  selection_other:
    CommandLine|contains:
      -' -m'
      -' a '

  condition:selection_password and selection_other
Falsepositives:
  -Legitimate use of Winrar command line version
  -Other command line tools, that use these flags
Level: high