Detection rules › Sigma

Data Compressed

Status
test
Severity
low
Log source
product linux, service auditd
Author
Timur Zinniatullin, oscd.community
Source
github.com/SigmaHQ/sigma

An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.

MITRE ATT&CK coverage

Rule body yaml

title: Data Compressed
id: a3b5e3e9-1b49-4119-8b8e-0344a01f21ee
status: test
description: An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/a78b9ed805ab9ea2e422e1aa7741e9407d82d7b1/atomics/T1560.001/T1560.001.md
author: Timur Zinniatullin, oscd.community
date: 2019-10-21
modified: 2023-07-28
tags:
    - attack.exfiltration
    - attack.collection
    - attack.t1560.001
logsource:
    product: linux
    service: auditd
detection:
    selection1:
        type: 'execve'
        a0: 'zip'
    selection2:
        type: 'execve'
        a0: 'gzip'
        a1: '-k'
    selection3:
        type: 'execve'
        a0: 'tar'
        a1|contains: '-c'
    condition: 1 of selection*
falsepositives:
    - Legitimate use of archiving tools by legitimate user.
level: low

Stages and Predicates

Stage 0: condition

1 of selection*

Stage 1: selection1

selection1:
    type: 'execve'
    a0: 'zip'

Stage 2: selection2

selection2:
    type: 'execve'
    a0: 'gzip'
    a1: '-k'

Stage 3: selection3

selection3:
    type: 'execve'
    a0: 'tar'
    a1|contains: '-c'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
a0eq
  • gzip
  • tar
  • zip
a1eq
  • -k
a1match
  • -c
typeeq
  • execve