LoFP LoFP / legitimate usage of sdelete

Techniques

Sample rules

Potential Secure Deletion with SDelete

Description

Detects files that have extensions commonly seen while SDelete is used to wipe files.

Detection logic

condition: selection
selection:
  EventID:
  - 4656
  - 4663
  - 4658
  ObjectName|endswith:
  - .AAA
  - .ZZZ