LoFP LoFP / t1070.004

t1070.004

TitleTags
administrator may execute this app to manage disk
administrator or network operator can execute this command. please update the filter macros to remove false positives.
false positives levels will differ depending on the environment. you can use a combination of parentimage and other keywords from the commandline field to filter legitimate activity
legitimate administration activities
legitimate usage of sdelete
legitime usage of sdelete
linux package installer/uninstaller may cause this event. please update you filter macro to remove false positives.
network admin can delete services unit configuration file as part of normal software installation. filter is needed.
network operator may use this batch command to delete recursively a directory or files within directory
other third party applications not listed.
user may execute and use this application
will be used sometimes by admins to clean up local flash space