{"id":"T1486","name":"Data Encrypted for Impact","url":"https://attack.mitre.org/techniques/T1486","tactics":["impact"],"platforms":["ESXi","IaaS","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0215","stix_id":"x-mitre-detection-strategy--d080a1b1-5ad1-45a1-8f7b-b736986c20d9","name":"Detection of Multi-Platform File Encryption for Impact","url":"https://attack.mitre.org/detectionstrategies/DET0215","analytics":[{"id":"AN0602","stix_id":"x-mitre-analytic--1155df11-eee4-4fdf-a354-15eda0e90d4c","name":"Analytic 0602","description":"High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.","url":"https://attack.mitre.org/detectionstrategies/DET0215#AN0602","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"FileExtension","description":"Non-standard or randomly generated file extensions may indicate encrypted content."},{"field":"TargetFolder","description":"Focus on user document folders, network shares, or system paths like %System32%."},{"field":"TimeWindow","description":"Correlate rapid writes and renames within seconds across high file count."},{"field":"CommandLine","description":"Flag common ransomware tools or functions (vssadmin delete shadows /all /quiet)."}],"live":true,"detection_strategies":["DET0215"],"techniques":["T1486"]},{"id":"AN0603","stix_id":"x-mitre-analytic--b2f444b1-e434-40e1-9501-6b66a05a0201","name":"Analytic 0603","description":"Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops.","url":"https://attack.mitre.org/detectionstrategies/DET0215#AN0603","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"openat, write, rename, unlink","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"FilenamePattern","description":"Look for creation of ransom note files (e.g., READ_ME.txt, HELP_DECRYPT.html)."},{"field":"SyscallBurstRate","description":"High write/open/unlink activity in short intervals indicates encryption attempts."},{"field":"DirectoryTargeted","description":"Correlate activity in /home, /etc, /opt, or mounted volumes."}],"live":true,"detection_strategies":["DET0215"],"techniques":["T1486"]},{"id":"AN0604","stix_id":"x-mitre-analytic--3b18d20b-94c7-41e7-8f82-99148945a74f","name":"Analytic 0604","description":"Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using `srm`, `gpg`, or compiled payloads. Often correlated with ransom note creation in multiple directories.","url":"https://attack.mitre.org/detectionstrategies/DET0215#AN0604","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"file encrypted|new file with .encrypted extension|disk write burst","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"exec srm|exec openssl|exec gpg","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ExtensionPattern","description":"Encrypted files may use .locked, .enc, or ransom-specific extensions."},{"field":"VolumeTargeted","description":"Detect activity targeting mounted external or backup volumes."}],"live":true,"detection_strategies":["DET0215"],"techniques":["T1486"]},{"id":"AN0605","stix_id":"x-mitre-analytic--203586e5-e178-4d41-bbae-93a86f04977b","name":"Analytic 0605","description":"Ransomware encrypts .vmdk, .vmx, .log, or VM config files in VMFS datastores. May rename to .locked or delete/overwrite with encrypted versions. Often correlates with shell commands run through `dcui`, SSH, or vSphere.","url":"https://attack.mitre.org/detectionstrategies/DET0215#AN0605","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"rename .vmdk to .*.locked|datastore write spike","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"esxi-vmkernel"},{"name":"esxi:shell","channel":"openssl|tar|dd","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"FileType","description":"Detect renames or write patterns involving .vmdk, .vmx, .nvram."},{"field":"UserContext","description":"Identify shell sessions opened by root or unexpected users outside maintenance window."}],"live":true,"detection_strategies":["DET0215"],"techniques":["T1486"]},{"id":"AN0606","stix_id":"x-mitre-analytic--57d8fd27-9af5-4d01-9d1a-fdde8ec0c902","name":"Analytic 0606","description":"Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.","url":"https://attack.mitre.org/detectionstrategies/DET0215#AN0606","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"PutObject (with SSE-C), UploadPart (SSE-C)","data_component":"DC0023","data_component_name":"Cloud Storage Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"SSEHeader","description":"SSE-C headers indicate attacker-controlled encryption keys."},{"field":"AffectedBucket","description":"Prioritize logs, backups, or shared document storage buckets."},{"field":"UserAgent","description":"Detect scripted automation vs console-based API behavior."}],"live":true,"detection_strategies":["DET0215"],"techniques":["T1486"]}],"live":true,"version":"1.0","techniques":["T1486"]}],"sigma_rules":[{"id":"0e0255bf-2548-47b8-9582-c0955c9283f5","title":"Suspicious Reg Add BitLocker","author":"frack113","status":"test","level":"high","date":"2021-11-15","modified":"2022-09-09","description":"Detects suspicious addition to BitLocker related registry keys via the reg.exe utility","references":["https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.t1486"],"path":"rules/windows/process_creation/proc_creation_win_reg_bitlocker.yml","techniques":["T1486"],"cves":[]},{"id":"1279262f-1464-422f-ac0d-5b545320c526","title":"AWS KMS Imported Key Material Usage","author":"toopricey","status":"experimental","level":"high","date":"2025-10-18","modified":null,"description":"Detects the import or deletion of key material in AWS KMS, which can be used as part of ransomware attacks. This activity is uncommon and provides a high certainty signal.\n","references":["https://www.chrisfarris.com/post/effective-aws-ransomware/","https://docs.aws.amazon.com/kms/latest/developerguide/ct-importkeymaterial.html","https://docs.aws.amazon.com/kms/latest/developerguide/ct-deleteimportedkeymaterial.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.impact","attack.t1486","attack.resource-development","attack.t1608.003"],"path":"rules/cloud/aws/cloudtrail/aws_kms_import_key_material.yml","techniques":["T1486","T1608.003"],"cves":[]},{"id":"16124c2d-e40b-4fcc-8f2c-5ab7870a2223","title":"AWS EC2 Disable EBS Encryption","author":"Sittikorn S","status":"stable","level":"medium","date":"2021-06-29","modified":"2021-08-20","description":"Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region.\nDisabling default encryption does not change the encryption status of your existing volumes.\n","references":["https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableEbsEncryptionByDefault.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.impact","attack.t1486","attack.t1565"],"path":"rules/cloud/aws/cloudtrail/aws_ec2_disable_encryption.yml","techniques":["T1486","T1565"],"cves":[]},{"id":"2c76a22b-702d-48fd-8fa9-e41e2fe203b3","title":"FunkLocker Ransomware File Creation","author":"Saiprashanth Pulisetti ( @Prashanthblogs)","status":"experimental","level":"high","date":"2025-08-08","modified":null,"description":"Detects the creation of files with the \".funksec\" extension, which is appended to encrypted files by the FunkLocker ransomware.","references":["https://www.broadcom.com/support/security-center/protection-bulletin/funksec-ransomware","https://www.pcrisk.com/removal-guides/31853-funklocker-funksec-ransomware"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.impact","attack.t1486","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/file_event_win_malware_funklocker_ransomware_extension.yml","techniques":["T1486"],"cves":[]},{"id":"3669afd2-9891-4534-a626-e5cf03810a61","title":"Load Of RstrtMgr.DLL By An Uncommon Process","author":"Luc Génaux","status":"test","level":"low","date":"2023-11-28","modified":"2026-07-28","description":"Detects the load of RstrtMgr DLL (Restart Manager) by an uncommon process.\nThis library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows.\nIt could also be used for anti-analysis purposes by shut downing specific processes.\n","references":["https://www.crowdstrike.com/blog/windows-restart-manager-part-1/","https://www.crowdstrike.com/blog/windows-restart-manager-part-2/","https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/","https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.impact","attack.defense-impairment","attack.t1486","attack.t1685"],"path":"rules/windows/image_load/image_load_dll_rstrtmgr_uncommon_load.yml","techniques":["T1486","T1685"],"cves":[]},{"id":"41d40bff-377a-43e2-8e1b-2e543069e079","title":"WannaCry Ransomware Activity","author":"Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro","status":"test","level":"critical","date":"2019-01-16","modified":"2025-10-18","description":"Detects WannaCry ransomware activity","references":["https://www.hybrid-analysis.com/sample/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa?environmentId=100","https://x.com/nas_bench/status/1868639048484425963"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.defense-impairment","attack.t1210","attack.discovery","attack.t1083","attack.t1222.001","attack.impact","attack.t1486","attack.t1490","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/WannaCry/proc_creation_win_malware_wannacry.yml","techniques":["T1210","T1083","T1222.001","T1486","T1490"],"cves":[]},{"id":"4c6ca276-d4d0-4a8c-9e4c-d69832f8671f","title":"Antivirus - Ransomware Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"test","level":"critical","date":"2022-05-12","modified":"2026-06-15","description":"Detects a highly relevant Antivirus alert that reports ransomware.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/43b0f7872900bd234975a0877744554f4f355dc57505517abd1ef611e1ce6916","https://www.virustotal.com/gui/file/c312c05ddbd227cbb08958876df2b69d0f7c1b09e5689eb9d93c5b357f63eff7","https://www.virustotal.com/gui/file/20179093c59bca3acc6ce9a4281e8462f577ffd29fd7bf51cf2a70d106062045","https://www.virustotal.com/gui/file/554db97ea82f17eba516e6a6fdb9dc04b1d25580a1eb8cb755eeb260ad0bd61d","https://www.virustotal.com/gui/file/69fe77dd558e281621418980040e2af89a2547d377d0f2875502005ce22bc95c","https://www.virustotal.com/gui/file/6f0f20da34396166df352bf301b3c59ef42b0bc67f52af3d541b0161c47ede05"],"logsource":{"category":"antivirus"},"tags":["attack.t1486","attack.impact"],"path":"rules/category/antivirus/av_ransomware.yml","techniques":["T1486"],"cves":[]},{"id":"689308fc-cfba-4f72-9897-796c1dc61487","title":"Potential Conti Ransomware Activity","author":"frack113","status":"test","level":"critical","date":"2021-10-12","modified":"2023-02-13","description":"Detects a specific command used by the Conti ransomware group","references":["https://news.sophos.com/en-us/2021/09/03/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks/","https://twitter.com/VK_Intel/status/1447795359900704769?t=Xz7vaLTvaaCZ5kHoZa6gMw&s=19"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.s0575","attack.t1486","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Conti/proc_creation_win_malware_conti_ransomware_commands.yml","techniques":["T1486"],"cves":[]},{"id":"74db3488-fd28-480a-95aa-b7af626de068","title":"LockerGoga Ransomware Activity","author":"Vasiliy Burov, oscd.community","status":"stable","level":"critical","date":"2020-10-18","modified":"2023-02-03","description":"Detects LockerGoga ransomware activity via specific command line.","references":["https://medium.com/@malwaredancer/lockergoga-input-arguments-ipc-communication-and-others-bd4e5a7ba80a","https://blog.f-secure.com/analysis-of-lockergoga-ransomware/","https://www.carbonblack.com/blog/tau-threat-intelligence-notification-lockergoga-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.t1486","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/LockerGoga/proc_creation_win_malware_lockergoga_ransomware.yml","techniques":["T1486"],"cves":[]},{"id":"77df53a5-1d78-4f32-bc5a-0e7465bd8f41","title":"Portable Gpg.EXE Execution","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-06","modified":"2023-11-10","description":"Detects the execution of \"gpg.exe\" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.","references":["https://www.trendmicro.com/vinfo/vn/threat-encyclopedia/malware/ransom.bat.zarlock.a","https://securelist.com/locked-out/68960/","https://github.com/redcanaryco/atomic-red-team/blob/c4097dc7ed14d7f7d08c89d148c4307097e8c294/atomics/T1486/T1486.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.t1486"],"path":"rules/windows/process_creation/proc_creation_win_gpg4win_portable_execution.yml","techniques":["T1486"],"cves":[]},{"id":"b48492dc-c5ef-4572-8dff-32bc241c15c8","title":"Load Of RstrtMgr.DLL By A Suspicious Process","author":"Luc Génaux","status":"test","level":"high","date":"2023-11-28","modified":null,"description":"Detects the load of RstrtMgr DLL (Restart Manager) by a suspicious process.\nThis library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows.\nIt could also be used for anti-analysis purposes by shut downing specific processes.\n","references":["https://www.crowdstrike.com/blog/windows-restart-manager-part-1/","https://www.crowdstrike.com/blog/windows-restart-manager-part-2/","https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/","https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.impact","attack.defense-impairment","attack.t1486","attack.t1685"],"path":"rules/windows/image_load/image_load_dll_rstrtmgr_suspicious_load.yml","techniques":["T1486","T1685"],"cves":[]},{"id":"bd132164-884a-48f1-aa2d-c6d646b04c69","title":"Microsoft 365 - Potential Ransomware Activity","author":"austinsonger","status":"test","level":"medium","date":"2021-08-19","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported when a user uploads files to the cloud that might be infected with ransomware.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.impact","attack.t1486"],"path":"rules/cloud/m365/threat_management/microsoft365_potential_ransomware_activity.yml","techniques":["T1486"],"cves":[]},{"id":"caf02a0a-1e1c-4552-9b48-5e070bd88d11","title":"Suspicious Creation TXT File in User Desktop","author":"frack113","status":"test","level":"medium","date":"2021-12-26","modified":"2026-01-09","description":"Detects creation of .txt files in user desktop folders via cmd.exe. This behavior may indicate ransomware deploying ransom notes, but can also occur during legitimate administrative tasks.\nAnalysts should investigate for suspicious filenames (e.g., \"RANSOM\", \"DECRYPT\", \"READ_ME\"), bulk file creation patterns, or concurrent encryption activity to determine if this is part of a ransomware attack.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1486/T1486.md#atomic-test-5---purelocker-ransom-note"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.impact","attack.t1486","detection.threat-hunting"],"path":"rules-threat-hunting/windows/file/file_event/file_event_win_susp_desktop_txt.yml","techniques":["T1486"],"cves":[]},{"id":"e3f673b3-65d1-4d80-9146-466f8b63fa99","title":"Suspicious Appended Extension","author":"frack113","status":"test","level":"medium","date":"2022-07-16","modified":"2023-11-11","description":"Detects file renames where the target filename uses an uncommon double extension. Could indicate potential ransomware activity renaming files and adding a custom extension to the encrypted files, such as \".jpg.crypted\", \".docx.locky\", etc.","references":["https://app.any.run/tasks/d66ead5a-faf4-4437-93aa-65785afaf9e5/","https://blog.cyble.com/2022/08/10/onyx-ransomware-renames-its-leak-site-to-vsop/"],"logsource":{"product":"windows","category":"file_rename"},"tags":["attack.impact","attack.t1486"],"path":"rules/windows/file/file_rename/file_rename_win_ransomware.yml","techniques":["T1486"],"cves":[]},{"id":"ec0722a3-eb5c-4a56-8ab2-bf6f20708592","title":"Renamed Gpg.EXE Execution","author":"Nasreddine Bencherchali (Nextron Systems), frack113","status":"test","level":"high","date":"2023-08-09","modified":null,"description":"Detects the execution of a renamed \"gpg.exe\". Often used by ransomware and loaders to decrypt/encrypt data.","references":["https://securelist.com/locked-out/68960/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.t1486"],"path":"rules/windows/process_creation/proc_creation_win_renamed_gpg4win.yml","techniques":["T1486"],"cves":[]},{"id":"eee8311f-a752-44f0-bf2f-6b007db16300","title":"BlueSky Ransomware Artefacts","author":"j4son","status":"test","level":"high","date":"2023-05-23","modified":null,"description":"Detect access to files and shares with names and extensions used by BlueSky ransomware which could indicate a current or previous encryption attempt.","references":["https://unit42.paloaltonetworks.com/bluesky-ransomware/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.impact","attack.t1486","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Malware/BlueSky-Ransomware/win_security_malware_bluesky_ransomware_files_indicators.yml","techniques":["T1486"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-38831","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-27532","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-36884","state":"stale","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-45046","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-28252","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-0669","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2015-8651","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-22947","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2009-3960","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2016-1019","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-44228","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-42258","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2019-11634","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-34473","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2020-1472","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}