Password Protected Compressed File Extraction Via 7Zip

Rule Info

Tags
attack.collection DEMO attack.t1560.001
Modified
None
Author
Nasreddine Bencherchali (Nextron Systems)
Name
Password Protected Compressed File Extraction Via 7Zip
Description
Detects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.
Date
2023-03-10 00:00:00
Id
b717b8fd-6467-4d7d-b3d3-27f9a463af77
Type
Community Rule

Rule History

Commit
Date
Author
Title
2023-03-11
Nasreddine Bencherchali
fix: add missing modifier
2023-03-10
Nasreddine Bencherchali
feat: more updates