LoFP LoFP / t1560.001

t1560.001

TitleTags
false positives should be limited as this behavior is not normal for `rundll32.exe` or `dllhost.exe` to spawn and run 7zip.
generally used to copy configs or ios images
highly likely if rar is a default archiver in the monitored environment.
legitimate activity is expected since compressing files with a password is common.
legitimate activity is expected since extracting files with a password can be common in some environment.
legitimate use of 7z to compress wer \".dmp\" files for troubleshooting
legitimate use of 7z with a command line in which \".dmp\" or \".dump\" appears accidentally
legitimate use of archiving tools by legitimate user.
legitimate use of winrar command line version
legitimate use of winrar in a folder of a software that bundles winrar
legitimate use of winrar to compress wer \".dmp\" files for troubleshooting
legitimate use of winrar with a command line in which \".dmp\" or \".dump\" appears accidentally
likely
limited false positives, however this analytic will need to be modified for each environment if sysmon is not used.
other command line tools, that use these flags
some false positives could occur with the admin or guest account. it depends on the scripts being used by the admins in your env. if you experience a lot of fp you could reduce the level to medium
user and network administrator can execute this command.