Backup Deletion

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query detects attempts to delete backups, which could be ransomware activity to prevent file restoration and disrupt business services.

Attribute Value
Type Hunting Query
Solution Endpoint Threat Protection Essentials
ID 56ebae61-89cf-42d9-99f4-3dff8ba33885
Tactics Impact
Techniques T1490
Required Connectors MicrosoftDefenderAdvancedThreatProtection, MicrosoftThreatProtection, WindowsSecurityEvents, WindowsForwardedEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceProcessEvents ?
SecurityEvent ?
WindowsEvent ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Endpoint Threat Protection Essentials