Data Staging via 7-Zip/WinRAR/tar with Password or Suspicious Output Path
Detects the execution of command-line archiving utilities (7z, rar, tar) invoked by common scripting engines (PowerShell, CMD, Python, etc.) targeting typical staging directories (Temp, Public, AppData, ProgramData). This pattern is frequently observed during the data staging phase of an attack, where adversaries encrypt or compress gathered files for eventual exfiltration.
SentinelOne

