Files
blue-team-tools/rules/linux/process_creation/proc_creation_lnx_file_deletion.yml
T
Nasreddine Bencherchali d03f6df250 Reference Update [Batch 1]
2022-07-07 15:24:15 +01:00

24 lines
791 B
YAML

title: File Deletion
id: 30aed7b6-d2c1-4eaf-9382-b6bc43e50c57
status: stable
description: Detects file deletion using "rm" or "shred" commands which are used often by adversaries to delete files left behind by the actions of their intrusion activity
author: Ömer Günal, oscd.community
date: 2020/10/07
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.004/T1070.004.md
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith:
- '/rm' # covers /rmdir as well
- '/shred'
condition: selection
falsepositives:
- Legitimate administration activities
level: informational
tags:
- attack.defense_evasion
- attack.t1070.004