Skip to content

Latest commit

 

History

History
6 lines (6 loc) · 412 Bytes

Delayed Deletion of Files.md

File metadata and controls

6 lines (6 loc) · 412 Bytes

Description

A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes use these techniques to cover their tracks.

Attacker's Goals

Evade security controls and possibly cover their tracks.

Investigative Actions

Check whether the executing process is benign, and if this was a desired behavior as part of its normal execution flow.