Actor
Detection engineers can identify potential data destruction attempts on Linux hosts by monitoring for the use of the 'rm' command with the '--no-preserve-root' flag, a technique utilized by the Awfulshred malware.