{"id":"1ddc1472-8e52-4f7d-9f11-eab14fc171f5","title":"PowerShell Decompress Commands","description":"A General detection for specific decompress commands in PowerShell logs. This could be an adversary decompressing files.","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"informational","date":"2020-05-02","modified":"2022-12-25","tags":["attack.stealth","attack.t1140"],"technique_ids":["T1140"],"logsource":{"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"},"falsepositives":["Unknown"],"references":["https://github.com/OTRF/detection-hackathon-apt29/issues/8","https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/4.A.3_09F29912-8E93-461E-9E89-3F06F6763383.md"],"source_path":"rules/windows/powershell/powershell_module/posh_pm_decompress_commands.yml","source_sha256":"b2728904de0dd6798342e85e72161b1e3286d5e19866ba3ddea4f9d5c2fa371c","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_module/posh_pm_decompress_commands.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: PowerShell Decompress Commands\nid: 1ddc1472-8e52-4f7d-9f11-eab14fc171f5\nrelated:\n    - id: 81fbdce6-ee49-485a-908d-1a728c5dcb09\n      type: derived\nstatus: test\ndescription: A General detection for specific decompress commands in PowerShell logs. This could be an adversary decompressing files.\nreferences:\n    - https://github.com/OTRF/detection-hackathon-apt29/issues/8\n    - https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/4.A.3_09F29912-8E93-461E-9E89-3F06F6763383.md\nauthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)\ndate: 2020-05-02\nmodified: 2022-12-25\ntags:\n    - attack.stealth\n    - attack.t1140\nlogsource:\n    product: windows\n    category: ps_module\n    definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b\ndetection:\n    selection_4103:\n        Payload|contains: 'Expand-Archive'\n    condition: selection_4103\nfalsepositives:\n    - Unknown\nlevel: informational\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1140","id":"T1140","name":"Deobfuscate/Decode Files or Information","page":"techniques/enterprise/T1140/"}],"data_path":"data/detection-rules/1ddc1472-8e52-4f7d-9f11-eab14fc171f5.json","kind":"sigma"}
