Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

18 detectors match the current filters. technique: T1070 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Accessing bash history file Clearing bash history file is a known procedure of attackers to delete traces. Low Platform Analytics Process execution Defense Evasion
BIOC Accessing bash history file using bash commands Clearing bash history files is a known attacker procedure for covering their tracks. Low Platform Analytics Process execution Defense Evasion
BIOC Clear logs - using dd and /dev/null Usage of the dd utility to clear the contents of a file using /dev/null. Medium Platform Analytics Process execution Defense Evasion
BIOC Clearing logs by copying /dev/null to a log file Usage of the cp command to copy /dev/null to a file and clear its content. Informational Platform Analytics Process execution Defense Evasion
BIOC Clearing logs by executing cat /dev/null Usage of cat /dev/null to clear the contents of a log file. Informational Platform Analytics Process execution Defense Evasion
BIOC Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. Informational Platform Analytics Process execution Defense Evasion, Impact
Analytics BIOC Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. Low Platform Analytics XDR Agent Defense Evasion
BIOC Delete Volume USN Journal with fsutil This technique is used by attackers to eliminate evidence of files created during post-exploitation activities. Medium Platform Analytics Process execution Defense Evasion
BIOC File timestamp tampering An attacker may modify file timestamps by running the touch command to hide their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Log deletion in known log file directories Deletion of log files in known log directories. Informational Platform Analytics File Defense Evasion
BIOC Log deletion using the truncate command Usage of the truncate utility using "-s 0" argument to clear log files. Informational Platform Analytics Process execution Defense Evasion
BIOC Log deletion via command-line tool An attacker may use the rm command to remove traces of their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Possible log destruction using the dd command Possible destruction of system log files using the dd command. Informational Platform Analytics File Defense Evasion
BIOC PowerShell is used to modify a timestamp Attackers may use PowerShell.exe to modify the timestamp of a file. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. Low Platform Analytics XDR Agent Defense Evasion
BIOC Windows event logs cleared using wmic.exe Attackers may clear events from Windows event logs to remove traces of their malicious activity. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. Informational Platform Analytics Windows event log Defense Evasion