Rule Info
Name
Deletion of RDP Log Files via Command Line
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects deletion of Remote Desktop Protocol (RDP) log files which may indicate ransomware or malicious activity attempting to impede forensic investigation
Date
2025-11-06 00:00:00
Modified
None
Id
7af429cd-3c1a-4dbd-bae5-01410e47dca6
Tags
attack.defense-evasion attack.t1070.001
Type
Nextron Sigma feed only (private)
