Open Cyb3rWard0g opened 4 years ago
The attacker deletes various files (T1107) associated with that access by reflectively loading and executing the Sdelete binary (T1055) within powershell.exe
Description
The attacker deletes various files (T1107) associated with that access by reflectively loading and executing the Sdelete binary (T1055) within powershell.exe