T1486 Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- LockerGoga Ransomware Activitycriticalstable · windows
- Antivirus - Ransomware Signaturecriticaltest · antivirus
- Potential Conti Ransomware Activitycriticaltest · windows
- WannaCry Ransomware Activitycriticaltest · windows
- BlueSky Ransomware Artefactshightest · windows
- Load Of RstrtMgr.DLL By A Suspicious Processhightest · windows
- Renamed Gpg.EXE Executionhightest · windows
- Suspicious Reg Add BitLockerhightest · windows
- AWS KMS Imported Key Material Usagehighexperimental · aws
- FunkLocker Ransomware File Creationhighexperimental · windows
- AWS EC2 Disable EBS Encryptionmediumstable · aws
- Microsoft 365 - Potential Ransomware Activitymediumtest · m365
- Portable Gpg.EXE Executionmediumtest · windows
- Suspicious Appended Extensionmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.