{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/winrar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["data-collection","threat-detection","windows","winrar"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eWinRAR and the associated command-line utility (RAR.exe) are frequently leveraged by threat actors to compress sensitive data for later exfiltration. While these tools are legitimate, attackers often rename or drop them into non-standard, user-writable directories to evade detection based on established file paths. This brief provides a detection mechanism to monitor for WinRAR process execution originating from locations other than its expected installation directory in Program Files. Defenders should focus on instances where RAR.exe or WinRAR.exe are executed from temporary folders, user profiles, or hidden directories, as this behavior is often indicative of collection activity during an intrusion.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful execution of WinRAR by unauthorized actors facilitates the collection and staging of local data, leading to information theft and potential privacy incidents. Identifying this technique allows security teams to disrupt the data collection phase of an attack before data is exfiltrated from the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to your SIEM to monitor for suspicious WinRAR executions. Use the rule to baseline legitimate software that may bundle WinRAR as a dependency. If alerts trigger, investigate the parent process and command-line arguments to determine if the execution is part of a malicious data collection chain.\u003c/p\u003e\n","date_modified":"2026-09-01T12:27:21Z","date_published":"2026-09-01T12:27:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-winrar-uncommon-folder/","summary":"Detection logic for identifying WinRAR execution from non-standard directories, a technique often used by attackers to stage archives for data collection and exfiltration.","title":"WinRAR Execution from Non-Standard Locations","url":"https://feed.craftedsignal.io/briefs/2026-09-winrar-uncommon-folder/"}],"language":"en","title":"CraftedSignal Threat Feed - Winrar","version":"https://jsonfeed.org/version/1.1"}