BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
6 BIOCs match the current filters. technique: T1560 ✕
Download CSV Show ATT&CK heatmap7z.exe execution with password protection parameters Informational Collection
7z.exe was executed with parameters indicating password protection of the output file.
Indicator:Process action type = execution AND target process cmd = *-p* AND target process name = 7z.exe Host host os = windows
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Command-line creation of a RAR archive Informational Exfiltration
Compression of data into a RAR archive using the rar.exe utility.
Indicator:Process action type = execution AND target process cmd = * a * AND target process name = rar.exe
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data (T1560)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Compressed archive created using tar Informational Collection
Attackers may use the tar built-in tool to stage a file for exfiltration.
Indicator:Process action type = execution AND target process cmd = *-cvzf* AND target process name = tar
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data (T1560)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Encrypted zip archive creation Informational Collection
Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive.
Indicator:Process action type = execution AND target process cmd = * -p* , * -e* , * --password* , * --encrypt* AND target process name = zip Host host os = macos , linux
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Rar.exe execution with password protection parameters Informational Collection
Rar.exe was executed with parameters indicating password protection of the output file.
Indicator:Process action type = execution AND target process cmd = *-hp* , *-p* AND target process name = rar.exe Host host os = windows
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Wzzip.exe execution with password protection parameters Informational Collection
Wzzip.exe was executed with parameters indicating password protection of the output file.
Indicator:Process action type = execution AND target process cmd = *-s* AND target process name = wzzip.exe Host host os = windows
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Archive Collected Data: Archive via Utility (T1560.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23