Skip to content
Sysmon

Sysmon Event ID 23: File deleted (archived)

FileDelete (File Delete archived)Sysmon event 23 logs a file deletion and saves a copy of the deleted file in the archive folder. Recovers payloads and tools attackers delete after use.
23
Event ID
23
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 23 means

Sysmon event 23 records a file being deleted, with the deleting process, the file path and its hashes — and Sysmon also keeps a copy of the file in the ArchiveDirectory (default C:\Sysmon, protected by a SYSTEM-only ACL). That makes it possible to recover droppers, scripts and tools that attackers remove to cover their tracks.

Archiving has a cost: the directory can grow very large, so rules should target interesting extensions and folders. Event 26 (FileDeleteDetected, Sysmon 13.10+) logs the same information without keeping the file.

When it is logged

Audit policy / configuration

Sysmon 11.0 or later with a <FileDelete> rule in the configuration. ArchiveDirectory sets where copies are stored.

Configuration entries such as CopyOnDeletePE, CopyOnDeleteExtensions and CopyOnDeleteProcesses control what is preserved. Monitor free disk space on hosts with broad rules.

Key fields

FieldWhat it tells you
ProcessGuidProcess that deleted the file.
ImageExecutable that deleted the file.
UserAccount of the process.
TargetFilenamePath of the deleted file.
HashesHashes of the deleted file, per HashAlgorithms.
IsExecutabletrue when the deleted file is a PE executable.
Archivedtrue when a copy was saved in the archive directory.

Common benign sources

  • Installers, updaters and cleanup tasks removing temporary files.
  • Browsers and Office deleting caches and temp files.

What attackers do that produces it

  • Droppers deleting themselves after launching the payload.
  • Operators removing tools, scripts and dump files from temp folders when done.
  • Ransomware deleting originals after writing encrypted copies.

Investigation tips

  • Retrieve the archived copy (named by hash) from the archive directory for analysis.
  • Pivot on ProcessGuid to event 1 and on TargetFilename to the earlier event 11 that created it.
  • Look for many deletions in a short time from one process (ransomware or wiper).

MITRE ATT&CK techniques

TechniqueTactics
T1070.004 Indicator Removal: File DeletionStealth
T1485 Data DestructionImpact
T1486 Data Encrypted for ImpactImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

12 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 3
  • Medium · 8
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading