File Deletion Via Del

 Original Source: [Sigma source]
Title: File Deletion Via Del
Status: test
Description:Detects execution of the builtin "del"/"erase" commands in order to delete files. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.004/T1070.004.md
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/erase
Author: frack113
Date: 2022-01-15
modified:2024-03-05
Tags:
  • -'attack.stealth'
  • -'attack.t1070.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_del:
    CommandLine|contains:
      -'del '
      -'erase '

  selection_flags:
    CommandLine|contains|windash:
      -' -f'
      -' -s'
      -' -q'

  condition:all of selection_*
Falsepositives:
  -False positives levels will differ Depending on the environment. You can use a combination of ParentImage and other keywords from the CommandLine field to filter legitimate activity
Level: low