Techniques
Sample rules
Uninstall Crowdstrike Falcon Sensor
- source: sigma
- technicques:
- t1562
- t1562.001
Description
Adversaries may disable security tools to avoid possible detection of their tools and activities by uninstalling Crowdstrike Falcon
Detection logic
condition: selection
selection:
CommandLine|contains|all:
- \WindowsSensor.exe
- ' /uninstall'
- ' /quiet'