Skip to content
Sysmon

Sysmon Event ID 26: File deleted (logged)

FileDeleteDetected (File Delete logged)Sysmon event 26 logs a file deletion with the deleting process and hashes but, unlike event 23, does not keep a copy. A low-cost way to track deletions.
26
Event ID
26
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 26 means

Sysmon event 26 records a file deletion: which process deleted which file, with its hashes and whether it was an executable. It carries the same information as event 23, minus the archived copy and the Archived field, so it does not fill the disk.

It is well suited to broad rules — watching deletions in temp, download and staging folders or deletions of executables — while event 23 is kept for narrow cases where the file itself must be preserved.

When it is logged

Audit policy / configuration

Sysmon 13.10 or later with a <FileDeleteDetected> rule in the configuration.

Key fields

FieldWhat it tells you
ProcessGuidProcess that deleted the file.
ImageExecutable that deleted the file.
UserAccount of the process.
TargetFilenamePath of the deleted file.
HashesHashes of the deleted file, which let you search for it elsewhere even though it is gone here.
IsExecutabletrue when the deleted file is a PE executable.

Common benign sources

  • Temp-file cleanup by applications, installers and Windows maintenance.
  • Users emptying folders or the Recycle Bin.

What attackers do that produces it

  • Self-deleting droppers and operators wiping tools after use.
  • Mass deletions by ransomware or wipers.

Investigation tips

  • Pivot on TargetFilename to the event 11 that created it and on ProcessGuid to event 1.
  • Use Hashes to find copies of the deleted file on other hosts.
  • Look for bursts of deletions from one process.

MITRE ATT&CK techniques

TechniqueTactics
T1070.004 Indicator Removal: File DeletionStealth
T1485 Data DestructionImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

12 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 3
  • Medium · 8
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading