Directory Removal Via Rmdir

 Original Source: [Sigma source]
Title: Directory Removal Via Rmdir
Status: test
Description:Detects execution of the builtin "rmdir" command in order to delete directories. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.004/T1070.004.md
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/erase
Author: frack113
Date: 2022-01-15
modified:2023-03-07
Tags:
  • -'attack.stealth'
  • -'attack.t1070.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_rmdir:
    CommandLine|contains: 'rmdir'
  selection_flags:
    CommandLine|contains:
      -'/s'
      -'/q'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: low