• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Post-encryption anti-forensic command sequence (WinRE, VSS, logs, free-space wip

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated 9 days ago•0•0•2

    Detects execution of common Windows utilities used by adversaries post-encryption to hinder system recovery and clear forensic evidence. This includes disabling the Windows Recovery Environment (ReAgentC), wiping disk free space (Cipher), clearing DNS caches, and clearing Windows Event Logs via Wevtutil or PowerShell.

    Sigma

    Tags

    T1685.005 - Clear Windows Event LogsT1490 - Inhibit System RecoveryT1485 - Data DestructionTA0040 - ImpactProcess CreationLog ClearedCommand ExecutionWindowsWindows Eventlog SystemWindows Eventlog SecurityWindows Eventlog ApplicationWindows Eventlog Powershellattack.defense_evasionattack.impactattack.t1070.001attack.t1070.004attack.t1490

    Found in

    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 20 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 20 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 20 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 20 days ago
    • Settra Ransomware Variant Deploys MeshAgent RMMLast updated 20 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?