Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution

Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Tom Ueltschi (SigmaHQ), DRL 1.1
Published
2019-01-16
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule matches process creation commands consistent with NotPetya ransomware behavior, including clearing Windows event logs with wevtutil and deleting the NTFS journal on drive C using fsutil. It also looks for rundll32.exe execution patterns that reference extracted payload data (e.g., .dat or .zip.dll) and a perfc-related marker file. These actions matter to attackers because they impair forensic visibility and support credential theft and malware execution; the rule relies on Windows process creation telemetry capturing image paths and command-line arguments.

Related detections9 linkedT1003.001 — drag to rearrange
Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Andromeda Loader Execution via Rundll32 Desktop.ini Ordinal
Suspicious rundll32 Execution of sqlite3 DLL by Ordinal with TLB Argument
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Malicious Credential Dumping via Mimikatz Sekurlsa Command
Malicious Mimikatz Sekurlsa Logonpasswords Credential Dump
Malicious Zardoor Backdoor Execution via rundll32 (via process_creation)
Malicious LSASS Credential Dump via ProcDump (via process_creation)
Malicious LSASS Memory Dump via comsvcs.dll by Salt Typhoon
Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Pivot detection · T1003.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.