Skip to content

Hide Navigation Hide TOC

File Deleted Via Sysinternals SDelete (6ddab845-b1b8-49c2-bbf7-1a11967f64bc)

Detects the deletion of files by the Sysinternals SDelete utility. It looks for the common name pattern used to rename files.

Cluster A Galaxy A Cluster B Galaxy B Level
File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern File Deleted Via Sysinternals SDelete (6ddab845-b1b8-49c2-bbf7-1a11967f64bc) Sigma-Rules 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) Attack Pattern 2