Selective Exclusion

T1679

Technique.View on attack.mitre.org

About this technique

Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution. Some file extensions that adversaries may avoid encrypting include `.dll`, `.exe`, and `.lnk`.

Adversaries may perform this behavior to avoid alerting users, to evade detection by security tools and analysts, or, in the case of ransomware, to ensure that the system remains operational enough to deliver the ransom notice.

Exclusions may target files and components whose corruption would cause instability, break core services, or immediately expose the attack. By carefully avoiding these areas, adversaries maintain system responsiveness while minimizing indicators that could trigger alarms or otherwise inhibit achieving their goals.

Detection rules0

Rules on DetectionCode tagged with T1679.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software6

Campaigns0

None recorded.

Procedure examples7

Groups1

Used byProcedure example
GroupVOID MANTICORE

VOID MANTICORE has avoided interacting with specific directories in order to reduce the likelihood of detection.

Software6

Used byProcedure example
MalwareDynoWiper

DynoWiper has recursively enumerated directories with the exception of the following: System32, Windows, Program Files, Program Files(x86), Temp, Recycle.Bin, $Recycle.Bin, Boot, PerfLogs, AppData, Documents and Settings.

MalwareEmbargo

Embargo has avoided encrypting specific files and directories by leveraging a regular expression within the ransomware binary.

MalwareInvisibleFerret

InvisibleFerret has the capability to scan for file names, file extensions, and avoids pre-designated path names and file types.

MalwareLazyWiper

LazyWiper can enumerate the hostname of the system to determine if it is a domain controller and exclude it from being wiped if so.

MalwareMedusa Ransomware

Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.

MalwareSameCoin

SameCoin can avoid overwriting file names that contain “desktop.ini” and “conf.conf."

References1

  1. Palo Alto Unit 42 Medusa Group Medusa Ransomware January 2024 Open source
    Anthony Galiette, Doel Santos. (2024, January 11). Medusa Ransomware Turning Your Files into Stone. Retrieved October 15, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.