T1485 Data Destruction — ATT&CK Technique
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as del and rm often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure. Adversaries may attempt to overwrite files and directories with randomly generated data to make it irrecoverable. In some cases politically oriented image files have been used to overwrite data. To maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware designed for destroying data may have worm-like features to propagate across a network by leveraging additional techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.. In cloud environments, adversaries may leverage access to delete cloud storage objects, machine images, database instances, and other infrastructure crucial to operations to damage an organization or their customers. Similarly, they may delete virtual machines from on-prem virtualized environments.
Detection coverage (50)
- Potential BlackByte Ransomware Activity high
- AWS EKS Cluster Created or Deleted low
- AWS EFS Fileshare Mount Modified or Deleted medium
- Azure Device or Configuration Modified or Deleted medium
- Azure Container Registry Created or Deleted low
- Azure Kubernetes Network Policy Change medium
- Azure Kubernetes Service Account Modified or Deleted medium
- Azure Kubernetes Cluster Created or Deleted low
- Azure Kubernetes Sensitive Role Access medium
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted medium
- Azure Kubernetes Secret or Config Object Access medium
- Microsoft 365 - Unusual Volume of File Deletion medium
- Overwriting the File with Dev Zero or Null low
- DD File Overwrite low
- MSSQL Destructive Query medium
- Potential Secure Deletion with SDelete medium
- Deleted Data Overwritten Via Cipher.EXE medium
- Fsutil Suspicious Invocation high
- Renamed Sysinternals Sdelete Execution high
- Potential File Overwrite Via Sysinternals SDelete high
- AWS Bedrock Delete Knowledge Base
- GitHub Enterprise Repository Deleted
- GitHub Enterprise Remove Organization
- GitHub Enterprise Repository Archived
- GitHub Organizations Repository Archived
- GitHub Organizations Repository Deleted
- O365 Email Hard Delete Excessive Volume
- O365 Email Password and Payroll Compromise Behavior
- O365 Email Receive and Hard Delete Takeover Behavior
- O365 Email Send and Hard Delete Exfiltration Behavior
- O365 Email Send and Hard Delete Suspicious Behavior
- O365 Email Send Attachments Excessive Volume
- Common Ransomware Extensions
- Common Ransomware Notes
- Excessive File Deletion In WinDefender Folder
- Linux Account Manipulation Of SSH Config and Keys
- Linux Auditd Data Destruction Command
- Linux Auditd Dd File Overwrite
- Linux Auditd Shred Overwrite Command
- Linux Data Destruction Command
- Linux Deletion Of Cron Jobs
- Linux Deletion Of Services
- Linux DD File Overwrite
- Linux Deleting Critical Directory Using RM Command
- Linux Deletion Of Init Daemon Script
- Linux Deletion of SSL Certificate
- Linux High Frequency Of File Deletion In Boot Folder
- Linux High Frequency Of File Deletion In Etc Folder
- Linux Shred Overwrite Command
- Sdelete Application Execution
Malware using this technique
- Diavol
- WhisperGate
- Industroyer
- Xbash
- AcidRain
- Shai-Hulud
- REvil
- Kazuar
- DynoWiper
- HermeticWiper
- SameCoin
- DEADWOOD
- Shamoon
- PowerDuke
- Olympic Destroyer
- MultiLayer Wiper
- CaddyWiper
- RawDisk
- LazyWiper
- SDelete
- BlackEnergy
- Meteor
- KillDisk
- ShrinkLocker
- Proxysvc
- Apostle
- AcidPour
- StoneDrill