Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 937 Bytes

MATCH-S00437.md

File metadata and controls

34 lines (27 loc) · 937 Bytes

Rules: Secure Deletion with SDelete

Description

Detects renaming of file with deletion with SDelete tool.

Additional Details

Detail Value
Type Templated Match
Category Impact
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Secure Deletion with SDelete
Summary Expression SDelete utility behavior detected on host: {{device_hostname}}
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0040, _mitreAttackTechnique:T1485

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema file_path
Normalized Schema metadata_deviceEventId
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema user_username