Detection rules › By event
Microsoft-Windows-Sysmon event 23
Sigma (12)
- ADS Zone.Identifier Deleted By Uncommon Application
- Backup Files Deleted
- EventLog EVTX File Deleted
- Exchange PowerShell Cmdlet History Deleted
- File Deleted Via Sysinternals SDelete
- IIS WebServer Access Logs Deleted
- PowerShell Console History Logs Deleted
- Prefetch File Deleted
- Process Deletion of Its Own Executable
- TeamViewer Log File Deleted
- Tomcat WebServer Logs Deleted
- Unusual File Deletion by Dns.exe
Splunk (8)
- Excessive File Deletion In WinDefender Folder
- Windows ConsoleHost History File Deletion
- Windows Data Destruction Recursive Exec Files Deletion
- Windows Default Rdp File Deletion
- Windows High File Deletion Frequency
- Windows Mark Of The Web Bypass
- Windows Rdp AutomaticDestinations Deletion
- Windows RDP Cache File Deletion