Cross-source coverage
T1486 / ATT&CK
Data Encrypted for Impact
548 rules · 396 families across 11 sources.
Showing deprecated and atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
In the case of ransomware, it is typical that common user files like Office documents, PDFs, images, videos, audio, text, and source code files will be encrypted (and often renamed and/or tagged with specific file markers). Adversaries may need to first employ other behaviors, such as File and Directory Permissions Modification or System Shutdown/Reboot, in order to unlock and/or gain access to manipulate these files. In some cases, adversaries may encrypt critical system files, disk partitions, and the MBR. Adversaries may also encrypt virtual machines hosted on ESXi or other hypervisors.
To maximize impact on the target organization, malware designed for encrypting data may have worm-like features to propagate across a network by leveraging other attack techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares. Encryption malware may also leverage Internal Defacement, such as changing victim wallpapers or ESXi server login messages, or otherwise intimidate victims by sending ransom notes or other messages to connected printers (known as "print bombing").
In cloud environments, storage objects within compromised accounts may also be encrypted. For example, in AWS environments, adversaries may leverage services such as AWS’s Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data.
- Tactics
- Impact
- Platforms
- ESXi · IaaS · Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogesxi:vmkernelesxi:shellAWS:CloudTrail
How MITRE says to detect it DET0215
Detection of Multi-Platform File Encryption for Impact
Windows Analytic 0602
High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=2
Linux Analytic 0603
Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops.
auditd:SYSCALLopenat, write, rename, unlinkauditd:SYSCALLexecve
macOS Analytic 0604
Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using `srm`, `gpg`, or compiled payloads. Often correlated with ransom note creation in multiple directories.
macos:unifiedlogfile encrypted|new file with .encrypted extension|disk write burstmacos:unifiedlogexec srm|exec openssl|exec gpg
ESXi Analytic 0605
Ransomware encrypts.vmdk,.vmx,.log, or VM config files in VMFS datastores. May rename to.locked or delete/overwrite with encrypted versions. Often correlates with shell commands run through `dcui`, SSH, or vSphere.
esxi:vmkernelrename .vmdk to .*.locked|datastore write spikeesxi:shellopenssl|tar|dd
IaaS Analytic 0606
Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.
AWS:CloudTrailPutObject (with SSE-C), UploadPart (SSE-C)
Emerging Threats Open
445 rules · 293 families| Detection | Severity | Format |
|---|---|---|
| ET MALWARE [ANY.RUN] RCRU64 Ransomware Variant CnC Activity | Critical | Suricata |
| ET DELETED ABUSE.CH Cerber Ransomware Domain Detected 2 variants | High | Suricata |
| ET DELETED ABUSE.CH Cerber Ransomware Domain Detected 2 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
| ET DELETED ABUSE.CH Ransomware Domain Detected 8 variants | High | Suricata |
+ 435 more from Emerging Threats Open → showing the 10 highest-severity
chronicle/detection-rules
18 rules| Detection | Severity | Format |
|---|---|---|
| darkgate_cryptocurrency_mining_and_ransomware_campaign_sysmon | Undefined | YARA-L |
| data_seondbin_ransomware_detector_sysmon_behavior | Undefined | YARA-L |
| nemty_successor_nefilimnephilim_ransomware | Undefined | YARA-L |
| netwalker_ransomware_detection | Undefined | YARA-L |
| paymen45_ransomware | Undefined | YARA-L |
| persistence_of_ryuk_ransomware | Undefined | YARA-L |
| rig_ek_delivers_predator_the_thiefbot_ransomware | Undefined | YARA-L |
| ryuk_encryption_and_evasion_techniques | Undefined | YARA-L |
| ryuk_ransomware_detector_sysmon_behavior | Undefined | YARA-L |
| ryuk_ransomware_hash_detected | Undefined | YARA-L |
+ 8 more from chronicle/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
16 rules| Detection | Severity | Format |
|---|---|---|
| Antivirus - Ransomware Signature | Critical | Sigma |
| LockerGoga Ransomware Activity | Critical | Sigma |
| Potential Conti Ransomware Activity | Critical | Sigma |
| WannaCry Ransomware Activity | Critical | Sigma |
| AWS KMS Imported Key Material Usage | High | Sigma |
| BlueSky Ransomware Artefacts | High | Sigma |
| FunkLocker Ransomware File Creation | High | Sigma |
| Load Of RstrtMgr.DLL By A Suspicious Process | High | Sigma |
| Renamed Gpg.EXE Execution | High | Sigma |
| Suspicious Reg Add BitLocker | High | Sigma |
+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
16 rules| Detection | Severity | Format |
|---|---|---|
| Excessive AWS S3 Object Encryption with SSE-C | High | Elastic TOML |
| Potential Ransomware Note File Dropped via SMB | High | Elastic TOML |
| Ransomware - Detected - Elastic Defend | High | Elastic TOML |
| Ransomware - Prevented - Elastic Defend | High | Elastic TOML |
| Suspicious File Renamed via SMB | High | Elastic TOML |
| Unusual AWS S3 Object Encryption with SSE-C | High | Elastic TOML |
| AWS S3 Object Encryption Using External KMS Key | Medium | Elastic TOML |
| Deprecated - M365 Security Compliance Potential Ransomware Activity | Medium | Elastic TOML |
| Potential AWS S3 Bucket Ransomware Note Uploaded | Medium | Elastic TOML |
| Potential Linux Ransomware Note Creation Detected | Medium | Elastic TOML |
+ 6 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
14 rules| Detection | Severity | Format |
|---|---|---|
| Slack Potentially Malicious File Shared | Critical | Panther Python |
| AWS S3 Object Exfiltration WITH Object Deletion | High | Panther Python |
| Azure Storage Blob CPK Encryption Detected | High | Panther Python |
| Azure Storage Blob Upload WITH CPK Encryption Error | High | Panther Python |
| GCP GCS Ransom Note Upload | High | Panther Python |
| S3 Object Encrypted with External KMS Key | High | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| AWS EC2 EBS Encryption Disabled | Medium | Panther Python |
| AWS S3 Object Copied to External Account Bucket | Medium | Panther Python |
| GCP GCS Bulk Object Rewrite Operation | Medium | Panther Python |
+ 4 more from panther-labs/panther-analysis → showing the 10 highest-severity
socfortress/Wazuh-Rules
10 rules| Detection | Severity | Format |
|---|---|---|
| File encryption using 7z with password (T1486) | High | Wazuh XML |
| File encryption using ccencrypt and password (T1486) | High | Wazuh XML |
| File encryption using GPG and AES-256 (T1486) | High | Wazuh XML |
| File encryption using OpenSSL rsautl with RSA public key (T1486) | High | Wazuh XML |
| Suspicious file encryption detected using gpg (T1027.009) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · DiskCryptor Execution (T1486) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · GPG4Win File Encryption (T1486) | High | Wazuh XML |
| Potential file encryption activity using 7z with password (T1022.001) | Medium | Wazuh XML |
| Suspicious encryption activity detected: use of ccencrypt binary (possible ransomware behavior). | Medium | Wazuh XML |
| Suspicious OpenSSL encryption or key generation activity detected (MITRE T1486) | Medium | Wazuh XML |
splunk/security_content
10 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS Detect Users creating keys with encrypt policy without MFA | Undefined | SPL |
| AWS Detect Users creating keys with encrypt policy without MFA | Undefined | SPL |
| AWS Detect Users with KMS keys performing encryption S3 | Undefined | SPL |
| High Process Termination Frequency | Undefined | SPL |
| Ransomware Notes bulk creation | Undefined | SPL |
| Ryuk Test Files Detected | Undefined | SPL |
| Samsam Test File Write | Undefined | SPL |
| Windows BitLocker Suspicious Command Usage | Undefined | SPL |
| Windows DiskCryptor Usage | Undefined | SPL |
| Windows .Key File Creation in Root Directory | Undefined | SPL |
Azure/Azure-Sentinel
6 rules| Detection | Severity | Format |
|---|---|---|
| AV detections related to Dev-0530 actors | High | KQL |
| AV detections related to Europium actors | High | KQL |
| AV detections related to Hive Ransomware | High | KQL |
| Dev-0530 File Extension Rename | High | KQL |
| ARS Ransomware Event triggered | Undefined | KQL |
| LockBit and related tool hash IoCs | Undefined | KQL |
elastic/protections-artifacts
6 rules| Detection | Severity | Format |
|---|---|---|
| DARKRADIATION Ransomware Infection | Undefined | Elastic TOML |
| Inhibit System Recovery Followed by a Suspicious File Rename | Undefined | Elastic TOML |
| Suspicious File Rename by an Unusual Process | Undefined | Elastic TOML |
| Suspicious File Rename from Unbacked Memory | Undefined | Elastic TOML |
| Suspicious File Rename via SMB | Undefined | Elastic TOML |
| VSS Service Disabled Followed by a Suspicious File Rename | Undefined | Elastic TOML |
Bert-JanP/Hunting-Queries-Detection-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| ASR Ransomware | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Monitor ransomwarelive for companies of interest on ransowmare data leak sites (DLS) | Undefined | KQL |
| RansomwareDoubleExtention | Undefined | KQL |
| Triggers when a known ransomware extension has been found | Undefined | KQL |