Tag
Detection of Windows Event Log Clearing via Wevtutil
1 rule 1 TTPThis brief details the detection of malicious Windows Event Log clearing using the native wevtutil utility, a common technique employed by ransomware groups to obstruct forensic investigations.
Detection of PowerShell-Based Timestomping Activity
1 rule 1 TTPAdversaries utilize PowerShell commands to modify file system metadata, specifically targeting creation, access, and modification timestamps to evade detection and hinder forensic analysis.
Suspicious Usage of Fsutil for Anti-Forensics and Data Destruction
1 rule 2 TTPsAdversaries, including ransomware operators, use the Windows fsutil utility to delete USN journals or truncate files to inhibit forensic analysis and support data destruction.
Detection of Windows Console History Clearing
1 rule 1 TTPAdversaries often attempt to clear PowerShell command history to conceal malicious activities conducted during a security incident.
Windows USN Journal Deletion via fsutil.exe
2 rules 1 TTPAdversaries may delete the USN journal on Windows systems using `fsutil.exe` to remove evidence of file modifications and other activities, hindering forensic investigations and incident response.