Suspicious Greedy Compression Using Rar.EXE — Detection Rule

Detects RAR usage that creates an archive from a suspicious folder, either a system folder or one of the folders often used by attackers for staging purposes

Read the full analysis on IntelFusions