Skip to content

S0195 SDelete

SDelete is an application that securely deletes data in a way that makes it unrecoverable. It is part of the Microsoft Sysinternals suite of tools. 1

Item Value
ID S0195
Associated Names
Type TOOL
Version 1.2
Created 18 April 2018
Last Modified 25 April 2025
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1485 Data Destruction SDelete deletes data in a way that makes it unrecoverable.1
enterprise T1070 Indicator Removal -
enterprise T1070.004 File Deletion SDelete deletes data in a way that makes it unrecoverable.1

Groups That Use This Software

ID Name References
G0016 APT29 2
G0034 Sandworm Team Sandworm Team has used SDelete for wartime operations in 2022-2023.3
G0080 Cobalt Group 4
G0053 FIN5 5
G0091 Silence 6

References