Techniques
Sample rules
Exchange PowerShell Cmdlet History Deleted
- source: sigma
- technicques:
- t1070
Description
Detects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence
Detection logic
condition: selection
selection:
TargetFilename|contains: _Cmdlet_
TargetFilename|startswith: \Logging\CmdletInfra\LocalPowerShell\Cmdlet\