Techniques › T1561 › T1561.001
T1561.001 Disk Content Wipe
impact — Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
1
Sigma rules tagged attack.t1561.001
0
KEV CVEs mapped here
<p>Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.</p><p>Adversaries may partially or completely overwrite the contents of a storage device rendering the data irrecoverable through the storage interface. Instead of wiping specific disk structures or files, adversaries with destructive intent may wipe arbitrary portions of disk content. To wipe disk content, adversaries may acquire direct access to the hard drive in order to overwrite arbitrarily sized portions of disk with random data. Adversaries have also been observed leveraging third-party drivers like RawDisk to directly access disk content. This behavior is distinct from Data Destruction because sections of the disk are erased instead of individual files.</p><p>To maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware used for wiping disk content may have worm-like features to propagate across a network by leveraging additional techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0316 Detection Strategy for Disk Content Wipe via Direct Access and Overwrite v1.0
AN0882 WindowsProcesses attempting raw disk access via \\.\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window.WinEventLog:Sysmon
Raw disk writes targeting \\.\PhysicalDrive* or MBR locations→ DC0046 Drive ModificationTunable:ProcessWhitelistTimeWindowAN0883 LinuxExecution of destructive utilities (dd, shred, wipe) targeting block devices, or processes invoking syscalls to directly overwrite /dev/sd* or /dev/nvme* partitions. Correlate abnormal file write attempts with shell process execution and block device access.auditd:EXECVEExecution of dd, shred, or wipe with arguments targeting block devices→ DC0032 Process CreationTunable:TargetDevicesEntropyThresholdAN0884 macOSAbnormal invocation of diskutil or asr with destructive flags (eraseDisk, zeroDisk), or low-level IOKit calls that overwrite raw disk content. Detect correlation between elevated process execution and disk erase operations.macos:unifiedlogdiskutil eraseDisk/zeroDisk or asr restore with destructive flags→ DC0064 Command Executionmacos:unifiedlogIOKit raw disk write activity targeting physical devices→ DC0046 Drive ModificationTunable:AdminToolWhitelistAN0885 Network DevicesExecution of CLI commands erasing file systems or storage (erase flash:, format disk, erase nvram:). Detect authentication events followed by destructive commands within the same privileged session.networkdevice:syslogPrivileged login followed by destructive command sequence→ DC0002 User Account AuthenticationTunable:PrivilegedUsersCommandPatterns
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1561.001
Author: Austin Clark
· 2019-08-12 (modified 2023-01-04) · logsource: product=cisco service=aaa · 71d65515-c436-43c0-841b-236b1f32c21e
See what files are being deleted from flash file systems