title: Data Compressed status: experimental description: An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network author: Timur Zinniatullin, oscd.community date: 2019/10/21 modified: 2019/11/04 references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1002/T1002.yaml logsource: product: windows service: powershell description: 'Script block logging must be enabled' detection: selection: EventID: 4104 keyword_1: - '*-Recurse*' keyword_2: - '*|*' keyword_3: - '*Compress-Archive*' condition: selection and all of keyword_* falsepositives: - highly likely if archive ops are done via PS level: low tags: - attack.exfiltration - attack.t1002