Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. technique: T1070 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Clearing logs by copying /dev/null to a log file Usage of the cp command to copy /dev/null to a file and clear its content. Informational Platform Analytics Process execution Defense Evasion
BIOC Clearing logs by executing cat /dev/null Usage of cat /dev/null to clear the contents of a log file. Informational Platform Analytics Process execution Defense Evasion
BIOC Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. Informational Platform Analytics Process execution Defense Evasion, Impact
BIOC File timestamp tampering An attacker may modify file timestamps by running the touch command to hide their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Log deletion in known log file directories Deletion of log files in known log directories. Informational Platform Analytics File Defense Evasion
BIOC Log deletion using the truncate command Usage of the truncate utility using "-s 0" argument to clear log files. Informational Platform Analytics Process execution Defense Evasion
BIOC Log deletion via command-line tool An attacker may use the rm command to remove traces of their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Possible log destruction using the dd command Possible destruction of system log files using the dd command. Informational Platform Analytics File Defense Evasion
BIOC PowerShell is used to modify a timestamp Attackers may use PowerShell.exe to modify the timestamp of a file. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. Informational Platform Analytics Windows event log Defense Evasion