Skip to content
Sysmon

Sysmon Event ID 28: File shredding blocked

FileBlockShreddingSysmon event 28 fires when Sysmon blocks a file-shredding attempt, such as SDelete overwriting a file before deleting it. Added in Sysmon 14.1.
28
Event ID
28
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 28 means

Sysmon event 28 is generated when Sysmon detects and blocks file shredding: overwriting a file's content before deleting it so it cannot be recovered, as done by tools such as Sysinternals SDelete. The file content is preserved.

Shredding is used by attackers and wipers to destroy evidence or data. On most business endpoints secure deletion is rare, so blocked attempts are worth reviewing, keeping in mind that some privacy and disk-cleaning tools do it on purpose.

When it is logged

Audit policy / configuration

Sysmon 14.1 or later with a <FileBlockShredding> rule in the configuration.

Key fields

FieldWhat it tells you
ProcessGuidProcess that attempted the shredding.
ImageExecutable that attempted the shredding, e.g. sdelete.exe or a renamed copy.
UserAccount of the process.
TargetFilenameFile the process tried to shred.
HashesHashes of the targeted file.
IsExecutabletrue when the targeted file is a PE executable.

Common benign sources

  • Administrators or privacy tools using SDelete or secure-erase features on purpose.

What attackers do that produces it

  • Operators shredding their tools, scripts or staged archives to hinder recovery.
  • Wipers overwriting user or system files.

Investigation tips

  • Pivot on ProcessGuid to event 1 to see the shredding tool and who launched it.
  • Review the targeted files — tools and dumps point to anti-forensics, business data to destruction.
  • Check for other deletions by the same process (events 23, 26).

MITRE ATT&CK techniques

TechniqueTactics
T1070.004 Indicator Removal: File DeletionStealth
T1485 Data DestructionImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading