Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters

Alerts when fsutil.exe is run with USN journal deletion/creation or setZeroData-style file zeroing commands.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Ecco, E.M. Anhaus, oscd.community (SigmaHQ), DRL 1.1
Published
2019-09-26
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags execution of fsutil.exe with command-line arguments commonly associated with USN Journal manipulation and file zeroing (deletejournal, createjournal, setZeroData). Attackers may use these actions to hinder forensic recovery by altering NTFS change tracking or to disrupt artifacts by overwriting with zeros. It relies on Windows process creation telemetry, matching on fsutil.exe by image/original filename and inspecting the command line for the listed parameters.

Related detections9 linkedT1485 — drag to rearrange
Malicious PathWiper Loader Script Execution from Windows Temp via WScript
Suspicious Free Space Wipe via cipher.exe
Suspicious sha256sum.exe Execution from Windows Temp Directory
Suspicious Browser History Wipe via Rundll32 ClearMyTracksByProcess (via process_creation)
Suspicious Secure Deletion of Free Space via Cipher (via process_creation)
USN Change Journal Deletion via Fsutil (via process_creation)
HamsaUpdate Wiper Trigger via F5UPDATER ConfirmDeleteFiles Argument (via process_creation)
Suspicious Salesforce Query History Deletion Anti-Forensics
Malicious Scheduled Task Deploying DYNOWIPER Payload (via process_creation)
Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters
Pivot detection · T1485 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.