T1561 — Disk Wipe

provenance: imported · ATT&CK: T1561

T1561: Disk Wipe

MITRE ATT&CK® Enterprise technique

Tactics Impact
Platforms Linux, macOS, Windows, Network Devices
Permissions required —
Version 1.2

Description

Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted.

To maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware used for wiping disks may have worm-like features to propagate across a network by leveraging additional techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.(Citation: Novetta Blockbuster Destructive Malware)

On network devices, adversaries may wipe configuration files and other data from the device using Network Device CLI commands such as erase.(Citation: erase_cmd_cisco)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1561
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/

See all 697 pages under Attacker techniques (ATT&CK) →

Related pages