BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • 7z.exe execution with password protection parameters Informational Collection

    7z.exe was executed with parameters indicating password protection of the output file.

    Indicator:

    Process action type = execution AND target process cmd = *-p* AND target process name = 7z.exe Host host os = windows

    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Command-line creation of a RAR archive Informational Exfiltration

    Compression of data into a RAR archive using the rar.exe utility.

    Indicator:

    Process action type = execution AND target process cmd = * a * AND target process name = rar.exe

    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Archive Collected Data (T1560)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Compressed archive created using tar Informational Collection

    Attackers may use the tar built-in tool to stage a file for exfiltration.

    Indicator:

    Process action type = execution AND target process cmd = *-cvzf* AND target process name = tar

    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Archive Collected Data (T1560)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Encrypted zip archive creation Informational Collection

    Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive.

    Indicator:

    Process action type = execution AND target process cmd = * -p* , * -e* , * --password* , * --encrypt* AND target process name = zip Host host os = macos , linux

    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Rar.exe execution with password protection parameters Informational Collection

    Rar.exe was executed with parameters indicating password protection of the output file.

    Indicator:

    Process action type = execution AND target process cmd = *-hp* , *-p* AND target process name = rar.exe Host host os = windows

    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Wzzip.exe execution with password protection parameters Informational Collection

    Wzzip.exe was executed with parameters indicating password protection of the output file.

    Indicator:

    Process action type = execution AND target process cmd = *-s* AND target process name = wzzip.exe Host host os = windows

    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23