Sysmon Event ID 23: File deleted (archived)
- Event ID
- 23
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 23 means
Sysmon event 23 records a file being deleted, with the deleting process, the file path and its hashes — and Sysmon also keeps a copy of the file in the ArchiveDirectory (default C:\Sysmon, protected by a SYSTEM-only ACL). That makes it possible to recover droppers, scripts and tools that attackers remove to cover their tracks.
Archiving has a cost: the directory can grow very large, so rules should target interesting extensions and folders. Event 26 (FileDeleteDetected, Sysmon 13.10+) logs the same information without keeping the file.
When it is logged
Sysmon 11.0 or later with a <FileDelete> rule in the configuration. ArchiveDirectory sets where copies are stored.
Configuration entries such as CopyOnDeletePE, CopyOnDeleteExtensions and CopyOnDeleteProcesses control what is preserved. Monitor free disk space on hosts with broad rules.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that deleted the file. |
| Image | Executable that deleted the file. |
| User | Account of the process. |
| TargetFilename | Path of the deleted file. |
| Hashes | Hashes of the deleted file, per HashAlgorithms. |
| IsExecutable | true when the deleted file is a PE executable. |
| Archived | true when a copy was saved in the archive directory. |
Common benign sources
- Installers, updaters and cleanup tasks removing temporary files.
- Browsers and Office deleting caches and temp files.
What attackers do that produces it
- Droppers deleting themselves after launching the payload.
- Operators removing tools, scripts and dump files from temp folders when done.
- Ransomware deleting originals after writing encrypted copies.
Investigation tips
- Retrieve the archived copy (named by hash) from the archive directory for analysis.
- Pivot on ProcessGuid to event 1 and on TargetFilename to the earlier event 11 that created it.
- Look for many deletions in a short time from one process (ransomware or wiper).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
12 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 3
- Medium · 8
- Low · 1
- HighExchange PowerShell Cmdlet History DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighPrefetch File DeletedRule by Cedric MAURUGEON, SigmaHQ, DRL 1.1
- HighUnusual File Deletion by Dns.exeRule by Tim Rauch (Nextron Systems), Elastic (idea), SigmaHQ, DRL 1.1
- MediumADS Zone.Identifier Deleted By Uncommon ApplicationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumBackup Files DeletedRule by frack113, SigmaHQ, DRL 1.1
- MediumEventLog EVTX File DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumFile Deleted Via Sysinternals SDeleteRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumIIS WebServer Access Logs DeletedRule by Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPowerShell Console History Logs DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumProcess Deletion of Its Own ExecutableRule by Max Altgelt (Nextron Systems), SigmaHQ, DRL 1.1
- MediumTomcat WebServer Logs DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- LowTeamViewer Log File DeletedRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.