Sysmon Event ID 26: File deleted (logged)
- Event ID
- 26
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 26 means
Sysmon event 26 records a file deletion: which process deleted which file, with its hashes and whether it was an executable. It carries the same information as event 23, minus the archived copy and the Archived field, so it does not fill the disk.
It is well suited to broad rules — watching deletions in temp, download and staging folders or deletions of executables — while event 23 is kept for narrow cases where the file itself must be preserved.
When it is logged
Sysmon 13.10 or later with a <FileDeleteDetected> rule in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that deleted the file. |
| Image | Executable that deleted the file. |
| User | Account of the process. |
| TargetFilename | Path of the deleted file. |
| Hashes | Hashes of the deleted file, which let you search for it elsewhere even though it is gone here. |
| IsExecutable | true when the deleted file is a PE executable. |
Common benign sources
- Temp-file cleanup by applications, installers and Windows maintenance.
- Users emptying folders or the Recycle Bin.
What attackers do that produces it
- Self-deleting droppers and operators wiping tools after use.
- Mass deletions by ransomware or wipers.
Investigation tips
- Pivot on TargetFilename to the event 11 that created it and on ProcessGuid to event 1.
- Use Hashes to find copies of the deleted file on other hosts.
- Look for bursts of deletions from one process.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
12 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 3
- Medium · 8
- Low · 1
- HighExchange PowerShell Cmdlet History DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- HighPrefetch File DeletedRule by Cedric MAURUGEON, SigmaHQ, DRL 1.1
- HighUnusual File Deletion by Dns.exeRule by Tim Rauch (Nextron Systems), Elastic (idea), SigmaHQ, DRL 1.1
- MediumADS Zone.Identifier Deleted By Uncommon ApplicationRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumBackup Files DeletedRule by frack113, SigmaHQ, DRL 1.1
- MediumEventLog EVTX File DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumFile Deleted Via Sysinternals SDeleteRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumIIS WebServer Access Logs DeletedRule by Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumPowerShell Console History Logs DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumProcess Deletion of Its Own ExecutableRule by Max Altgelt (Nextron Systems), SigmaHQ, DRL 1.1
- MediumTomcat WebServer Logs DeletedRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- LowTeamViewer Log File DeletedRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.