Techniques
Sample rules
Overwriting the File with Dev Zero or Null
- source: sigma
- technicques:
- t1485
Description
Detects overwriting (effectively wiping/deleting) of a file.
Detection logic
condition: selection
selection:
a0|contains: dd
a1|contains:
- if=/dev/null
- if=/dev/zero
type: EXECVE