Suspicious Self-Delete via cmd choice Timeout and Del

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-21
Updated
2026-09-21

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the cmd choice command used as a timing delay chained with a Del to remove the launching file. Ande Loader used a choice based countdown before deleting itself to erase the dropper after 0bj3ctivity Stealer was staged. This choice plus Del idiom is an anti forensic self cleanup pattern seen across loaders.

Related detections9 linkedT1070.004 — drag to rearrange
Suspicious Ping Loopback Delay Followed by File Deletion for Evasion
Suspicious Alternate Data Stream Self-Deletion via process_creation
Suspicious Crontab Removal via Command Line (via process_creation)
Suspicious Self-Deletion via Ping Loopback and Del (via process_creation)
Malicious Self-Deletion Via Fsutil SetZeroData
Self-Deletion via Ping Loopback Delay and Del Command
Suspicious Deletion of Explorer RunMRU Values
Suspicious PowerShell Self-Delete Of Executable via Process Creation
Suspicious Prefetch Deletion for Anti-Forensics
Suspicious Self-Delete via cmd choice Timeout and Del
Pivot detection · T1070.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.