ZEROLOT Wiper Mass File Deletion via PowerShell or cmd.exe (T1485)
This rule detects potential wiper activity by monitoring for high-frequency deletion or modification of specific file types (e.g., .docx, .xlsx, .pdf, .db, .bak) within a short window. It triggers when a process like PowerShell or Cmd is observed executing destructive commands (e.g., 'del', 'erase', 'Remove-Item') on a large number of files across multiple directories, which is a common behavior of malware attempting to destroy data.
Microsoft Sentinel (KQL)

