LoFP LoFP / t1560

t1560

TitleTags
false positives should be limited as this behavior is not normal for `rundll32.exe` or `dllhost.exe` to spawn and run 7zip.
generally used to copy configs or ios images
highly likely if rar is a default archiver in the monitored environment.
legitimate activity is expected since compressing files with a password is common.
legitimate usage of hdiutil by administrators and users.
legitimate use of 7z to compress wer \".dmp\" files for troubleshooting
legitimate use of 7z with a command line in which \".dmp\" or \".dump\" appears accidentally
legitimate use of archiving tools by legitimate user.
legitimate use of winrar command line version
legitimate use of winrar in a folder of a software that bundles winrar
legitimate use of winrar to compress wer \".dmp\" files for troubleshooting
legitimate use of winrar with a command line in which \".dmp\" or \".dump\" appears accidentally
likely
limited false positives, however this analytic will need to be modified for each environment if sysmon is not used.
other command line tools, that use these flags
powershell may used this function to archive data.
some false positives could occur with the admin or guest account. it depends on the scripts being used by the admins in your env. if you experience a lot of fp you could reduce the level to medium
user and network administrator can execute this command.