kevmap

TechniquesT1486 › AN0602

AN0602 Analytic 0602

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.</p>
Detects
T1486 Data Encrypted for Impact
Part of
DET0215 Detection of Multi-Platform File Encryption for Impact

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=11DC0039 File Creation
WinEventLog:SysmonEventCode=2DC0061 File Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
FileExtensionNon-standard or randomly generated file extensions may indicate encrypted content.
TargetFolderFocus on user document folders, network shares, or system paths like %System32%.
TimeWindowCorrelate rapid writes and renames within seconds across high file count.
CommandLineFlag common ransomware tools or functions (vssadmin delete shadows /all /quiet).

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2023-38831RARLAB WinRARMapped