// MITRE ATT&CK
T1486 · Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key....
How to detect & mitigate it
Detecting Data Encrypted for Impact starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1561.002
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1499.003
Application Exhaustion Flood T1561
Disk Wipe
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1499.003
Application Exhaustion Flood T1561
Disk Wipe
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.