{"id":"T1561.001","name":"Disk Content Wipe","url":"https://attack.mitre.org/techniques/T1561/001","tactics":["impact"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0316","stix_id":"x-mitre-detection-strategy--3a016ed2-47e0-414b-b90e-a44d1437354e","name":"Detection Strategy for Disk Content Wipe via Direct Access and Overwrite","url":"https://attack.mitre.org/detectionstrategies/DET0316","analytics":[{"id":"AN0882","stix_id":"x-mitre-analytic--d1ad1b0b-0050-4737-8993-73c2da8d143b","name":"Analytic 0882","description":"Processes attempting raw disk access via \\\\.\\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window.","url":"https://attack.mitre.org/detectionstrategies/DET0316#AN0882","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4673","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"Raw disk writes targeting \\\\.\\PhysicalDrive* or MBR locations","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ProcessWhitelist","description":"Backup, forensics, or imaging tools may perform legitimate raw disk access — requires tuning per environment."},{"field":"TimeWindow","description":"Correlation threshold for process execution, driver load, and raw disk writes."}],"live":true,"detection_strategies":["DET0316"],"techniques":["T1561.001"]},{"id":"AN0883","stix_id":"x-mitre-analytic--b55c84a0-d045-43f6-a5a9-e8f6edbd275e","name":"Analytic 0883","description":"Execution of destructive utilities (dd, shred, wipe) targeting block devices, or processes invoking syscalls to directly overwrite /dev/sd* or /dev/nvme* partitions. Correlate abnormal file write attempts with shell process execution and block device access.","url":"https://attack.mitre.org/detectionstrategies/DET0316#AN0883","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/write syscalls to block devices (/dev/sd*, /dev/nvme*)","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"Execution of dd, shred, or wipe with arguments targeting block devices","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"TargetDevices","description":"Exclude removable drives or designated partitions that may be overwritten during maintenance."},{"field":"EntropyThreshold","description":"Tune detection for pseudorandom write patterns to reduce false positives during high-volume I/O."}],"live":true,"detection_strategies":["DET0316"],"techniques":["T1561.001"]},{"id":"AN0884","stix_id":"x-mitre-analytic--1065ad69-8969-4ae0-9df6-dc7e7b1129c2","name":"Analytic 0884","description":"Abnormal invocation of diskutil or asr with destructive flags (eraseDisk, zeroDisk), or low-level IOKit calls that overwrite raw disk content. Detect correlation between elevated process execution and disk erase operations.","url":"https://attack.mitre.org/detectionstrategies/DET0316#AN0884","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"diskutil eraseDisk/zeroDisk or asr restore with destructive flags","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"IOKit raw disk write activity targeting physical devices","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AdminToolWhitelist","description":"Provisioning workflows may legitimately use diskutil/asr — whitelist by user or system context."}],"live":true,"detection_strategies":["DET0316"],"techniques":["T1561.001"]},{"id":"AN0885","stix_id":"x-mitre-analytic--d0e64036-83fb-4ff7-b81b-9b67b6c6b9dc","name":"Analytic 0885","description":"Execution of CLI commands erasing file systems or storage (erase flash:, format disk, erase nvram:). Detect authentication events followed by destructive commands within the same privileged session.","url":"https://attack.mitre.org/detectionstrategies/DET0316#AN0885","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"erase flash:, erase nvram:, format disk","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"},{"name":"networkdevice:syslog","channel":"Privileged login followed by destructive command sequence","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"PrivilegedUsers","description":"Tune to exclude approved maintenance performed by authorized administrators."},{"field":"CommandPatterns","description":"Expand or narrow destructive command coverage depending on vendor-specific syntax."}],"live":true,"detection_strategies":["DET0316"],"techniques":["T1561.001"]}],"live":true,"version":"1.0","techniques":["T1561.001"]}],"sigma_rules":[{"id":"71d65515-c436-43c0-841b-236b1f32c21e","title":"Cisco File Deletion","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-12","modified":"2023-01-04","description":"See what files are being deleted from flash file systems","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.impact","attack.stealth","attack.t1070.004","attack.t1561.001","attack.t1561.002"],"path":"rules/network/cisco/aaa/cisco_cli_file_deletion.yml","techniques":["T1070.004","T1561.001","T1561.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}