Potential File Overwrite Via Sysinternals SDelete (a4824fca-976f-4964-b334-0621379e84c4)
Detects the use of SDelete to erase a file not the free space
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Data Destruction - T1485 (d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c) | Attack Pattern | Potential File Overwrite Via Sysinternals SDelete (a4824fca-976f-4964-b334-0621379e84c4) | Sigma-Rules | 1 |