Backup Deletion

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query detects attempts to delete backups, which could be ransomware activity to prevent file restoration and disrupt business services.

Attribute Value
Type Hunting Query
Solution Endpoint Threat Protection Essentials
ID 56ebae61-89cf-42d9-99f4-3dff8ba33885
Tactics Impact
Techniques T1490
Required Connectors MicrosoftDefenderAdvancedThreatProtection, MicrosoftThreatProtection, WindowsSecurityEvents, WindowsForwardedEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceProcessEvents ?
SecurityEvent
WindowsEvent

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Endpoint Threat Protection Essentials