Sysmon Event ID 28: File shredding blocked
- Event ID
- 28
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 28 means
Sysmon event 28 is generated when Sysmon detects and blocks file shredding: overwriting a file's content before deleting it so it cannot be recovered, as done by tools such as Sysinternals SDelete. The file content is preserved.
Shredding is used by attackers and wipers to destroy evidence or data. On most business endpoints secure deletion is rare, so blocked attempts are worth reviewing, keeping in mind that some privacy and disk-cleaning tools do it on purpose.
When it is logged
Sysmon 14.1 or later with a <FileBlockShredding> rule in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| ProcessGuid | Process that attempted the shredding. |
| Image | Executable that attempted the shredding, e.g. sdelete.exe or a renamed copy. |
| User | Account of the process. |
| TargetFilename | File the process tried to shred. |
| Hashes | Hashes of the targeted file. |
| IsExecutable | true when the targeted file is a PE executable. |
Common benign sources
- Administrators or privacy tools using SDelete or secure-erase features on purpose.
What attackers do that produces it
- Operators shredding their tools, scripts or staged archives to hinder recovery.
- Wipers overwriting user or system files.
Investigation tips
- Pivot on ProcessGuid to event 1 to see the shredding tool and who launched it.
- Review the targeted files — tools and dumps point to anti-forensics, business data to destruction.
- Check for other deletions by the same process (events 23, 26).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighSysmon Blocked File ShreddingRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.