%GoCortexIO Snippets

Cortex XSIAM

Thwart anti-forensic cover-ups by detecting the intentional wiping of the NTFS USN change journal, a deliberate tactic used by adversaries to erase digital footprints and hinder incident response investigations.

| 5 minutes to implement | ~1 min read
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.

# Snippet - USN change journal deletion.

## Senario 

Imagine an actor who has finished their hands-on activity and clears the NTFS USN change journal to frustrate forensic timelining. The
`fsutil usn deletejournal` command is the standard means and is rarely run in normal operations.

Logic: very low base rate; almost any hit warrants triage. The `causality_actor_process_image_name` will usually be `cmd.exe` or `powershell.exe` for operator activity.


- [https://attack.mitre.org/techniques/T1070/](https://attack.mitre.org/techniques/T1070/)
- [https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-usn)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter lowercase(action_process_image_name) = "fsutil.exe"
| filter lowercase(action_process_image_command_line) contains "usn"
    and lowercase(action_process_image_command_line) contains "deletejournal"
| fields _time, agent_hostname, actor_effective_username,
    causality_actor_process_image_name, action_process_image_command_line
| limit 100
See all 21 snippets