LoFP LoFP / possible fp during log rotation

Techniques

Sample rules

Exchange PowerShell Cmdlet History Deleted

Description

Detects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence

Detection logic

condition: selection
selection:
  TargetFilename|contains: _Cmdlet_
  TargetFilename|startswith: \Logging\CmdletInfra\LocalPowerShell\Cmdlet\