ADS Zone.Identifier Deleted By Uncommon Application

Rule Info

Name
ADS Zone.Identifier Deleted By Uncommon Application
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
Date
2023-09-04 00:00:00
Modified
None
Id
3109530e-ab47-4cc6-a953-cac5ebcc93ae
Tags
attack.defense_evasion attack.t1070.004 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
frack113
Merge PR #4419 from @frack113 - New Rules Related To Zone.Identifier ADS Deletion
2023-09-06