Log source category
file_delete log source Sigma rules
14 Sigma detection rules in the library use the file_delete log source, mostly on windows. The file_delete category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Exchange PowerShell Cmdlet History Deleted
highDetects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence
windows
Potential PrintNightmare Exploitation Attempt
highDetect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675
windows
Prefetch File Deleted
highDetects the deletion of a prefetch file which may indicate an attempt to destroy forensic evidence
windows
Unusual File Deletion by Dns.exe
highDetects an unexpected file being deleted by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows
ADS Zone.Identifier Deleted By Uncommon Application
mediumDetects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
windows
Backup Files Deleted
mediumDetects deletion of files with extensions often used for backup files. Adversaries may delete or remove built-in operating system data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
windows
EventLog EVTX File Deleted
mediumDetects the deletion of the event log files which may indicate an attempt to destroy forensic evidence
windows
File Deleted Via Sysinternals SDelete
mediumDetects the deletion of files by the Sysinternals SDelete utility. It looks for the common name pattern used to rename files.
windows
IIS WebServer Access Logs Deleted
mediumDetects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence
windows
PowerShell Console History Logs Deleted
mediumDetects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence
windows
Process Deletion of Its Own Executable
mediumDetects the deletion of a process's executable by itself. This is usually not possible without workarounds and may be used by malware to hide its traces.
windows
Tomcat WebServer Logs Deleted
mediumDetects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence
windows
ADS Zone.Identifier Deleted
lowDetects the deletion of the "Zone.Identifier" ADS. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
windows
TeamViewer Log File Deleted
lowDetects the deletion of the TeamViewer log files which may indicate an attempt to destroy forensic evidence
windows