Potential Secure Deletion with SDelete
Detects files that have extensions commonly seen while SDelete is used to wipe files.
Sigma rule (View on GitHub)
1title: Potential Secure Deletion with SDelete
2id: 39a80702-d7ca-4a83-b776-525b1f86a36d
3status: test
4description: Detects files that have extensions commonly seen while SDelete is used to wipe files.
5references:
6 - https://jpcertcc.github.io/ToolAnalysisResultSheet/details/sdelete.htm
7 - https://www.jpcert.or.jp/english/pub/sr/ir_research.html
8 - https://learn.microsoft.com/en-gb/sysinternals/downloads/sdelete
9author: Thomas Patzke
10date: 2017-06-14
11modified: 2024-12-13
12tags:
13 - attack.impact
14 - attack.stealth
15 - attack.defense-impairment
16 - attack.t1070.004
17 - attack.t1027.005
18 - attack.t1485
19 - attack.t1553.002
20 - attack.s0195
21logsource:
22 product: windows
23 service: security
24detection:
25 selection:
26 EventID:
27 - 4656
28 - 4663
29 - 4658
30 ObjectName|endswith:
31 - '.AAA'
32 - '.ZZZ'
33 condition: selection
34falsepositives:
35 - Legitimate usage of SDelete
36 - Files that are interacted with that have these extensions legitimately
37level: medium
References
Related rules
- Cisco File Deletion
- Fsutil Suspicious Invocation
- Potential BlackByte Ransomware Activity
- ADS Zone.Identifier Deleted By Uncommon Application
- ASLR Disabled Via Sysctl or Direct Syscall - Linux