T1485 Data Destruction
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives.(Citation: Symantec Shamoon 2012)(Citation: FireEye Shamoon Nov 2016)(Citation: Palo…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Fsutil Suspicious Invocationhighstable · windows
- Potential BlackByte Ransomware Activityhightest · windows
- Potential File Overwrite Via Sysinternals SDeletehightest · windows
- Renamed Sysinternals Sdelete Executionhightest · windows
- AWS EFS Fileshare Mount Modified or Deletedmediumtest · aws
- Azure Device or Configuration Modified or Deletedmediumtest · azure
- Azure Kubernetes Network Policy Changemediumtest · azure
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deletedmediumtest · azure
- Azure Kubernetes Secret or Config Object Accessmediumtest · azure
- Azure Kubernetes Sensitive Role Accessmediumtest · azure
- Azure Kubernetes Service Account Modified or Deletedmediumtest · azure
- Deleted Data Overwritten Via Cipher.EXEmediumtest · windows
- Microsoft 365 - Unusual Volume of File Deletionmediumtest · m365
- Potential Secure Deletion with SDeletemediumtest · windows
- MSSQL Destructive Querymediumexperimental · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.