Detection rules › By event
Microsoft-Windows-Sysmon event 26
Sigma (12)
- ADS Zone.Identifier Deleted By Uncommon Application
- Backup Files Deleted
- EventLog EVTX File Deleted
- Exchange PowerShell Cmdlet History Deleted
- File Deleted Via Sysinternals SDelete
- IIS WebServer Access Logs Deleted
- PowerShell Console History Logs Deleted
- Prefetch File Deleted
- Process Deletion of Its Own Executable
- TeamViewer Log File Deleted
- Tomcat WebServer Logs Deleted
- Unusual File Deletion by Dns.exe