I was analyzing some malware at work that creates a hidden directory and executes code from that hidden directory. Malwarebytes was used to remove the malware directory from the infected machine. I wanted to confirm that the directory had been deleted by querying one directory up from the malware directory and Osquery reported it was but our EDR product said the directory still existed.