Cortex XSIAM
Thwart anti-forensic cover-ups by detecting the intentional wiping of the NTFS USN change journal, a deliberate tactic used by adversaries to erase digital footprints and hinder incident response investigations.
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.
# Snippet - USN change journal deletion.
## Senario
Imagine an actor who has finished their hands-on activity and clears the NTFS USN change journal to frustrate forensic timelining. The
`fsutil usn deletejournal` command is the standard means and is rarely run in normal operations.
Logic: very low base rate; almost any hit warrants triage. The `causality_actor_process_image_name` will usually be `cmd.exe` or `powershell.exe` for operator activity.
- [https://attack.mitre.org/techniques/T1070/](https://attack.mitre.org/techniques/T1070/)
- [https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter lowercase(action_process_image_name) = "fsutil.exe"
| filter lowercase(action_process_image_command_line) contains "usn"
and lowercase(action_process_image_command_line) contains "deletejournal"
| fields _time, agent_hostname, actor_effective_username,
causality_actor_process_image_name, action_process_image_command_line
| limit 100