Tag
medium
advisory
Detection of Windows Indicator Removal via Rmdir
1 rule 1 TTPAdversaries use the Windows 'rmdir' utility with recursive and quiet flags to systematically purge forensic artifacts, malware components, and temporary directories to hinder incident response efforts.
defense-evasion
malware
indicator-removal
1r
1t
medium
advisory
WebServer Access Logs Deleted
2 rules 1 TTPDetection of web server access log deletion across Windows, Linux, and macOS systems indicates potential defense evasion and destruction of forensic evidence by threat actors.
defense-evasion
indicator-removal
file-deletion
2r
1t