Post-encryption anti-forensic command sequence (WinRE, VSS, logs, free-space wip
Detects execution of common Windows utilities used by adversaries post-encryption to hinder system recovery and clear forensic evidence. This includes disabling the Windows Recovery Environment (ReAgentC), wiping disk free space (Cipher), clearing DNS caches, and clearing Windows Event Logs via Wevtutil or PowerShell.
Sigma

