SDelete

MITRE ATT&CK: S0195 View on attack.mitre.org

Aliases: SDelete

Malware type
wiper
Operating systems
windows
Profile updated
2026-07-07 15:33:01

Context

SDelete is an application that securely deletes data in a way that makes it unrecoverable. It is part of the Microsoft Sysinternals suite of tools.

Detection coverage

  • 1 YARA rules
  • 32 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Data Destruction (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Suspected_Sandworm_Sdelete_Wiper (yara-rule)

Reports & references

  • MITRE ATT&CK — S0195 (report)
  • Microsoft — Sdelete (report)

External references