Techniques
Sample rules
WinRAR Execution in Non-Standard Folder
- source: sigma
- technicques:- t1560
- t1560.001
 
Description
Detects a suspicious WinRAR execution in a folder which is not the default installation folder
Detection logic
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
filter_main_path:
  Image|contains:
  - :\Program Files (x86)\WinRAR\
  - :\Program Files\WinRAR\
filter_main_unrar:
  Image|endswith: \UnRAR.exe
filter_optional_temp:
  Image|contains: :\Windows\Temp\
selection:
- Image|endswith:
  - \rar.exe
  - \winrar.exe
- Description:
  - Command line RAR
  - WinRAR
