Suspicious Self-Deletion via Choice Timer and Del Command via Cmd (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-24
Updated
2026-09-24

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the self-deletion idiom that chains choice.exe as a timer with a forced Del command, used by the Deadglyph implant to remove its own components after execution. This anti-forensic cleanup destroys the dropper to hinder analysis and attribution.

Related detections9 linkedT1070.004 — drag to rearrange
Suspicious Jump List AutomaticDestinations Deletion via Cmd (via process_creation)
Suspicious Self-Delete via cmd choice Timeout and Del
Suspicious Ping Loopback Delay Followed by File Deletion for Evasion
Suspicious Alternate Data Stream Self-Deletion via process_creation
Suspicious Crontab Removal via Command Line (via process_creation)
Suspicious Self-Deletion via Ping Loopback and Del (via process_creation)
Malicious Self-Deletion Via Fsutil SetZeroData
Self-Deletion via Ping Loopback Delay and Del Command
Suspicious Deletion of Explorer RunMRU Values
Suspicious Self-Deletion via Choice Timer and Del Command via Cmd (via process_creation)
Pivot detection · T1070.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.