Suspicious Bulk Deletion of Executables or Libraries
This rule detects when a single process account initiates the deletion of 10 or more executable (.exe), dynamic link library (.dll), or system (.sys) files within a 5-minute window on a device. This behavior can be indicative of malicious activity such as malware cleanup, anti-forensics, or an attempt to disrupt system functionality.
Microsoft Sentinel (KQL)

