Technique with 2 sub-techniques.View on attack.mitre.org
Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted.
To maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware used for wiping disks may have worm-like features to propagate across a network by leveraging additional techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.
On network devices, adversaries may wipe configuration files and other data from the device using Network Device CLI commands such as `erase`.
Rules on DetectionCode tagged with T1561 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Cisco File Deletion | medium | cisco / NULL | T1561.001 T1561.002 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Microsoft Intune Bulk Wipe | TTP | NULL | Azure Monitor Activity | T1561.001 |
| Windows Raw Access To Disk Volume Partition | Anomaly | NULL | Sysmon EventID 9 | T1561.002 |
| Windows Raw Access To Master Boot Record Drive | TTP | NULL | Sysmon EventID 9 | T1561.002 |
None recorded.
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.