Suspicious Self-Deletion of Dropper via Command Line

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-04
Updated
2026-10-04

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects a command shell chaining a short delay with deletion of the just-executed binary, a self-removal technique used by the Ryuk dropper to erase traces after payload deployment. Adversaries combine ping or timeout with del to allow the parent to exit before the file is removed. This anti-forensic pattern is rarely produced by legitimate software.

Related detections9 linkedT1070.004 — drag to rearrange
Suspicious Zone.Identifier Mark-of-the-Web Removal (via process_creation)
Suspicious Self-Deletion via Choice Timer and Del Command via Cmd (via process_creation)
Suspicious Jump List AutomaticDestinations Deletion via Cmd (via process_creation)
Suspicious Self-Delete via cmd choice Timeout and Del
Suspicious Ping Loopback Delay Followed by File Deletion for Evasion
Suspicious Alternate Data Stream Self-Deletion via process_creation
Suspicious Crontab Removal via Command Line (via process_creation)
Suspicious Self-Deletion via Ping Loopback and Del (via process_creation)
Malicious Self-Deletion Via Fsutil SetZeroData
Suspicious Self-Deletion of Dropper via Command Line
Pivot detection · T1070.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.