Renamed Sysinternals Sdelete Execution

 Original Source: [Sigma source]
Title: Renamed Sysinternals Sdelete Execution
Status: test
Description:Detects the use of a renamed SysInternals Sdelete, which is something an administrator shouldn't do (the renaming)
References:
  -https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1485/T1485.md
Author: Florian Roth (Nextron Systems)
Date: 2022-09-06
modified:2026-06-29
Tags:
  • -'attack.impact'
  • -'attack.t1485'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    OriginalFileName: 'sdelete.exe'
  filter:
    Image|endswith:
      -'\sdelete.exe'
      -'\sdelete64.exe'
      -'\sdelete64a.exe'

  condition:selection and not filter
Falsepositives:
  -System administrator usage
Level: high