Skip to content
Threat Feed

Tag

Anti-Forensics

5 briefs RSS
medium advisory

Detection of Windows Event Log Clearing via Wevtutil

This brief details the detection of malicious Windows Event Log clearing using the native wevtutil utility, a common technique employed by ransomware groups to obstruct forensic investigations.

Windows anti-forensics defense-evasion ransomware
1r 1t
medium advisory

Detection of PowerShell-Based Timestomping Activity

Adversaries utilize PowerShell commands to modify file system metadata, specifically targeting creation, access, and modification timestamps to evade detection and hinder forensic analysis.

anti-forensics powershell stealth
1r 1t
high advisory

Suspicious Usage of Fsutil for Anti-Forensics and Data Destruction

Adversaries, including ransomware operators, use the Windows fsutil utility to delete USN journals or truncate files to inhibit forensic analysis and support data destruction.

anti-forensics persistence impact windows
1r 2t
high advisory

Detection of Windows Console History Clearing

Adversaries often attempt to clear PowerShell command history to conceal malicious activities conducted during a security incident.

anti-forensics powershell stealth
1r 1t
low advisory

Windows USN Journal Deletion via fsutil.exe

Adversaries may delete the USN journal on Windows systems using `fsutil.exe` to remove evidence of file modifications and other activities, hindering forensic investigations and incident response.

Windows defense-evasion anti-forensics fsutil
2r 1t