Forum Discussion
Paragon06
Sep 13, 2022Copper Contributor
Defender365 Alerts for high volume file deletion
All of a sudden we're getting large volumes of alerts from Defender for unusual volume of file deletions. We seldom get these and when we do it has previously turned out to be a user clearing old fil...
Steve Whitcher
Sep 15, 2022Bronze Contributor
Paragon06 You're not alone, others have been getting these alerts again recently as well. I opened a support ticket about it, as this seems like the rule is obviously broken when it's alerting constantly on routine programmatic deletion of files from the local appdata folder, but the rep just insists that this is how it's supposed to work, and if I don't like it I should turn the rule off (and possibly create a replacement rule that is more targeted.) Maybe someone else will have better luck than I did at convincing them that the rule/detection is broken.
There are other threads that have been discussing this on & off issue for a while, here's one:
Re: Unusual volume of file deletion - Microsoft Tech Community