File Deletion Via Del
Description
Detects execution of the builtin "del"/"erase" commands in order to delete files. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
Query · sigma
selection_img: - Image|endswith: \cmd.exe - OriginalFileName: Cmd.Exe selection_del: CommandLine|contains: - 'del ' - 'erase ' selection_flags: CommandLine|contains|windash: - ' -f' - ' -s' - ' -q' condition: all of selection_*
Known false positives
- False positives levels will differ Depending on the environment. You can use a combination of ParentImage and other keywords from the CommandLine field to filter legitimate activity