Renamed Sysinternals Sdelete Execution (c1d867fe-8d95-4487-aab4-e53f2d339f90)
Detects the use of a renamed SysInternals Sdelete, which is something an administrator shouldn't do (the renaming)
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Data Destruction - T1485 (d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c) | Attack Pattern | Renamed Sysinternals Sdelete Execution (c1d867fe-8d95-4487-aab4-e53f2d339f90) | Sigma-Rules | 1 |