Process execution from compressed file via Explorer
Detects child processes commonly used for code execution that are spawned from compressed files when initiated from Windows Explorer. Adversaries can leverage archives to deliver malicious executables and scripts for execution.
- Platform: Windows
- Severity: High
- MITRE Tactic: Execution
- MITRE Techniques: T1204, T1204.002