Forum Discussion

AnalystGuy's avatar
AnalystGuy
Copper Contributor
Nov 05, 2020

Hunting for deletion events

I was reading about a ransomware strain that deletes any folder called "System Volume Information" in an effort to prevent recovery, so I went to setup a hunting query or detection for that event.  B...

Resources