Files
splunk-security_content/stories/data_destruction.yml
2022-02-15 11:04:28 +01:00

23 lines
998 B
YAML

name: Data Destruction
id: 4ae5c0d1-cebd-47d1-bfce-71bf096e38aa
version: 1
date: '2022-02-14'
author: Teoderick Contreras, Splunk
description: Leverage searches that allow you to detect and investigate unusual activities
that might relate to the data destruction, including deleting files, overwriting files, wiping disk and encrypting files.
narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption
is the goal.
references:
- https://attack.mitre.org/techniques/T1485/
- https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
- https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware
tags:
analytic_story: Data Destruction
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection