2026 Critical Enterprise Intrusion Chain Detection: In-Memory Archive Staging and Webhook Exfiltration of Stolen Browser Data

This rule detects typical behavior associated with infostealers targeting browser data, specifically the creation of compressed archives (.zip, .rar) in temporary directories (Temp or AppData) and the subsequent exfiltration of data via known webhook services (e.g., Discord, Telegram, Pastebin) or direct IP connections. It filters out common signed backup and synchronization software to minimize noise.