{"id":"T1027.015","name":"Compression","url":"https://attack.mitre.org/techniques/T1027/015","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0281","stix_id":"x-mitre-detection-strategy--f3d5d1d5-3d80-46b2-be05-f0c438625230","name":"Detection Strategy for Compressed Payload Creation and Execution","url":"https://attack.mitre.org/detectionstrategies/DET0281","analytics":[{"id":"AN0782","stix_id":"x-mitre-analytic--18253101-bce9-453e-ab03-603bbd174552","name":"Analytic 0782","description":"Monitors for compression tool usage (e.g., 7zip, WinRAR, MakeCab) that follows or precedes file modification, suspicious file types (e.g., .exe, .dll) being compressed, or dropped from self-extracting archives followed by immediate execution.","url":"https://attack.mitre.org/detectionstrategies/DET0281#AN0782","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CompressedFileType","description":"Zip, .rar, .cab, .gz – tune based on expected legitimate use of compression in environment"},{"field":"SFXExecutionDelay","description":"Expected time between archive unpacking and first execution – short delays are suspicious"},{"field":"UserContext","description":"Restrict detection to non-admin or interactive users if excessive FPs from sys admin activity"}],"live":true,"detection_strategies":["DET0281"],"techniques":["T1027.015"]},{"id":"AN0783","stix_id":"x-mitre-analytic--55083ce8-b00e-4501-97db-829082bdbb48","name":"Analytic 0783","description":"Detects sequential command-line compression utilities (e.g., gzip, tar, zip, 7z) followed by execution of unpacked files, especially in temp directories or under non-standard locations like /dev/shm or /tmp with ELF binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0281#AN0783","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"openat","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"chmod","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"PathRegex","description":"Flag compressed archives extracted to /tmp, /dev/shm, or user’s home dir"},{"field":"CompressionToolPatterns","description":"gzip, tar, bzip2, xz, 7z – tune to suppress admin packaging workflows"},{"field":"ExecutionAfterUnpackWindow","description":"How soon a new file is executed after it’s unpacked"}],"live":true,"detection_strategies":["DET0281"],"techniques":["T1027.015"]},{"id":"AN0784","stix_id":"x-mitre-analytic--62afd8a1-550d-43a6-a56a-7d5ae5abbcf6","name":"Analytic 0784","description":"Identifies archive utilities (e.g., ditto, unzip, xar, pkgutil) used to extract payloads to non-standard paths, then correlates with execution or file permission changes (e.g., `chmod +x`) and process spawns from decompressed location.","url":"https://attack.mitre.org/detectionstrategies/DET0281#AN0784","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process launch","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"filesystem events","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"file open/write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"DecompressionPathMatch","description":"Target unusual extraction paths (~/Library/, /tmp/, /private/tmp/)"},{"field":"ToolBinaryNames","description":"List of decompression utilities used in the environment"},{"field":"FollowOnExecutionDelta","description":"Time between decompression and first binary execution"}],"live":true,"detection_strategies":["DET0281"],"techniques":["T1027.015"]}],"live":true,"version":"1.0","techniques":["T1027.015"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}