Skip to content

S0195 SDelete

SDelete is an application that securely deletes data in a way that makes it unrecoverable. It is part of the Microsoft Sysinternals suite of tools. 1

Item Value
ID S0195
Associated Names
Type TOOL
Version 1.2
Created 18 April 2018
Last Modified 12 August 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1485 Data Destruction SDelete deletes data in a way that makes it unrecoverable.1
enterprise T1070 Indicator Removal -
enterprise T1070.004 File Deletion SDelete deletes data in a way that makes it unrecoverable.1

Groups That Use This Software

ID Name References
G0053 FIN5 2
G0080 Cobalt Group 3
G0091 Silence 4
G0016 APT29 5

References