SMTP Data Exfiltration - Archive Attachment Outbound via Port 25/587
This rule detects the outbound transmission of email attachments via SMTP (ports 25 and 587) that contain archived file formats (zip, 7z, tar.gz, tgz). Attackers often compress collected data into archives to facilitate exfiltration and minimize the time required for data transfer.
Suricata

