mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
23 lines
998 B
YAML
23 lines
998 B
YAML
name: Data Destruction
|
|
id: 4ae5c0d1-cebd-47d1-bfce-71bf096e38aa
|
|
version: 1
|
|
date: '2022-02-14'
|
|
author: Teoderick Contreras, Splunk
|
|
description: Leverage searches that allow you to detect and investigate unusual activities
|
|
that might relate to the data destruction, including deleting files, overwriting files, wiping disk and encrypting files.
|
|
narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption
|
|
is the goal.
|
|
references:
|
|
- https://attack.mitre.org/techniques/T1485/
|
|
- https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
|
|
- https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware
|
|
tags:
|
|
analytic_story: Data Destruction
|
|
category:
|
|
- Malware
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|