Windows Security Events Indicating File Deletion Attempts Using SDelete Extensions

Alerts on Windows security file access events for object names ending in .AAA or .ZZZ, consistent with secure deletion behavior.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Thomas Patzke (SigmaHQ), DRL 1.1
Published
2017-06-14
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule flags Windows security events where file objects end with extensions commonly associated with SDelete operations. An attacker could use secure deletion tools to hinder recovery and reduce forensic evidence on targeted systems. The detection relies on Windows file access auditing events (Event IDs 4656, 4663, and 4658) and matches object names by their filename suffixes ('.AAA' or '.ZZZ').

Related detections9 linkedT1485 — drag to rearrange
Malicious PathWiper Loader Script Execution from Windows Temp via WScript
Suspicious Free Space Wipe via cipher.exe
Suspicious sha256sum.exe Execution from Windows Temp Directory
Suspicious Secure Deletion of Free Space via Cipher (via process_creation)
HamsaUpdate Wiper Trigger via F5UPDATER ConfirmDeleteFiles Argument (via process_creation)
Suspicious Crontab Removal via Command Line (via process_creation)
Suspicious Self-Deletion via Ping Loopback and Del (via process_creation)
Malicious Scheduled Task Deploying DYNOWIPER Payload (via process_creation)
Malicious Self-Deletion Via Fsutil SetZeroData
Windows Security Events Indicating File Deletion Attempts Using SDelete Extensions
Pivot detection · T1485 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.