mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3.7 KiB
3.7 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | |||||
|---|---|---|---|---|---|---|---|---|---|
| Data Destruction | 2022-02-14 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
Leverage searches that allow you to detect and investigate unusual activities that might relate to the data destruction, including deleting files, overwriting files, wiping disk and encrypting files.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2022-02-14
- Author: Teoderick Contreras, Splunk
- ID: 4ae5c0d1-cebd-47d1-bfce-71bf096e38aa
Narrative
Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal.
Detections
Reference
- https://attack.mitre.org/techniques/T1485/
- https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
- https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware
source | version: 1