LoFP LoFP / legitimate usage of sdelete

Techniques

Sample rules

Secure Deletion with SDelete

Description

Detects renaming of file while deletion with SDelete tool.

Detection logic

condition: selection
selection:
  EventID:
  - 4656
  - 4663
  - 4658
  ObjectName|endswith:
  - .AAA
  - .ZZZ