Potential Secure Deletion with SDelete

 Original Source: [Sigma source]
Title: Potential Secure Deletion with SDelete
Status: test
Description:Detects files that have extensions commonly seen while SDelete is used to wipe files.
References:
  -https://jpcertcc.github.io/ToolAnalysisResultSheet/details/sdelete.htm
  -https://www.jpcert.or.jp/english/pub/sr/ir_research.html
  -https://learn.microsoft.com/en-gb/sysinternals/downloads/sdelete
Author: Thomas Patzke
Date: 2017-06-14
modified:2024-12-13
Tags:
  • -'attack.impact'
  • -'attack.stealth'
  • -'attack.defense-impairment'
  • -'attack.t1070.004'
  • -'attack.t1027.005'
  • -'attack.t1485'
  • -'attack.t1553.002'
  • -'attack.s0195'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID:
      -'4656'
      -'4663'
      -'4658'

    ObjectName|endswith:
      -'.AAA'
      -'.ZZZ'

  condition:selection
Falsepositives:
  -Legitimate usage of SDelete
  -Files that are interacted with that have these extensions legitimately
Level: medium