This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Greedy File Deletion Using Del
Original Source:
[Sigma source]
Title:
Greedy File Deletion Using Del
Status:
test
Description:
Detects execution of the "del" builtin command to remove files using greedy/wildcard expression. This is often used by malware to delete content of folders that perhaps contains the initial malware infection or to delete evidence.
References:
-https://www.joesandbox.com/analysis/509330/0/html#1044F3BDBE3BB6F734E357235F4D5898582D
-https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/erase
Author:
frack113 , X__Junior (Nextron Systems)
Date:
2021-12-02
modified:
2023-09-11
Tags:
-'attack.stealth'
-'attack.t1070.004'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\cmd.exe'
OriginalFileName
:
'Cmd.Exe'
selection_del:
CommandLine|contains
:
-'del '
-'erase '
selection_extensions:
CommandLine|contains
:
-'\\\*.au3'
-'\\\*.dll'
-'\\\*.exe'
-'\\\*.js'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
medium