DET0758 Detection of Data Destruction
| Item |
Value |
| ID |
DET0758 |
| Version |
1.0 |
| Created |
21 October 2025 |
| Last Modified |
21 October 2025 |
Technique Detected: T0809 (Data Destruction)
Analytics
ICS
AN1890
Monitor for changes made to a large quantity of files for unexpected modifications in both user directories and directories used to store programs and OS components (e.g., C:\Windows\System32).
Monitor for newly executed processes of binaries that could be involved in data destruction activity, such as SDelete.
Monitor for unexpected deletion of files.
Monitor executed commands and arguments for binaries that could be involved in data destruction activity, such as SDelete.
Log Sources
Mutable Elements