Skip to content

Conversation

@morriscode
Copy link
Member

This rule detects 7z archive attachments that contain RAR files, which may be used to evade detection by nesting compressed file formats.

Description

This rule detects 7z archive attachments that contain RAR files, which may be used to evade detection by nesting compressed file formats.

Associated samples

Associated hunts

This rule detects 7z archive attachments that contain RAR files, which may be used to evade detection by nesting compressed file formats.
@morriscode morriscode requested a review from a team as a code owner November 4, 2025 15:06
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 4, 2025
@morriscode morriscode added the review-needed Indicates that a PR is waiting for review label Nov 8, 2025
@zoomequipd zoomequipd added this pull request to the merge queue Nov 8, 2025
Merged via the queue into main with commit edaae03 Nov 8, 2025
2 checks passed
@zoomequipd zoomequipd deleted the morriscode-patch-8 branch November 8, 2025 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants