Cross-source coverage

T1486 / ATT&CK

Data Encrypted for Impact

359 rules · 305 families across 10 sources.

189 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

In the case of ransomware, it is typical that common user files like Office documents, PDFs, images, videos, audio, text, and source code files will be encrypted (and often renamed and/or tagged with specific file markers). Adversaries may need to first employ other behaviors, such as File and Directory Permissions Modification or System Shutdown/Reboot, in order to unlock and/or gain access to manipulate these files. In some cases, adversaries may encrypt critical system files, disk partitions, and the MBR. Adversaries may also encrypt virtual machines hosted on ESXi or other hypervisors.

To maximize impact on the target organization, malware designed for encrypting data may have worm-like features to propagate across a network by leveraging other attack techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares. Encryption malware may also leverage Internal Defacement, such as changing victim wallpapers or ESXi server login messages, or otherwise intimidate victims by sending ransom notes or other messages to connected printers (known as "print bombing").

In cloud environments, storage objects within compromised accounts may also be encrypted. For example, in AWS environments, adversaries may leverage services such as AWS’s Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data.

Tactics
Impact
Platforms
ESXi · IaaS · Linux · macOS · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLmacos:unifiedlogesxi:vmkernelesxi:shellAWS:CloudTrail

How MITRE says to detect it DET0215

Detection of Multi-Platform File Encryption for Impact

Windows Analytic 0602

High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=2

Linux Analytic 0603

Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops.

  • auditd:SYSCALL openat, write, rename, unlink
  • auditd:SYSCALL execve

macOS Analytic 0604

Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using `srm`, `gpg`, or compiled payloads. Often correlated with ransom note creation in multiple directories.

  • macos:unifiedlog file encrypted|new file with .encrypted extension|disk write burst
  • macos:unifiedlog exec srm|exec openssl|exec gpg

ESXi Analytic 0605

Ransomware encrypts.vmdk,.vmx,.log, or VM config files in VMFS datastores. May rename to.locked or delete/overwrite with encrypted versions. Often correlates with shell commands run through `dcui`, SSH, or vSphere.

  • esxi:vmkernel rename .vmdk to .*.locked|datastore write spike
  • esxi:shell openssl|tar|dd

IaaS Analytic 0606

Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.

  • AWS:CloudTrail PutObject (with SSE-C), UploadPart (SSE-C)

Emerging Threats Open

275 rules · 221 families
Detection Severity Format
ET MALWARE [ANY.RUN] RCRU64 Ransomware Variant CnC Activity Critical Suricata
ET INFO Lockbit Ransomware Related Domain in DNS Lookup (bigblog .at) High Suricata
ET INFO Lockbit Ransomware Related Domain in DNS Lookup (decoding .at) High Suricata
ET INFO Lockbit Ransomware Related Domain in DNS Lookup (lockbit-decryptor .top) High Suricata
ET JA3 Hash - [Abuse.ch] Possible Ransomware High Suricata
ET JA3 Hash - [Abuse.ch] Possible Troldesh Ransomware High Suricata
ET MALWARE 7ev3n Ransomware Related Activity (GET) High Suricata
ET MALWARE ABUSE.CH Ransomware/Cerber Onion Domain Lookup 7 variants High Suricata
ET MALWARE ABUSE.CH Ransomware/Cerber Onion Domain Lookup 7 variants High Suricata
ET MALWARE ABUSE.CH Ransomware/Cerber Onion Domain Lookup 7 variants High Suricata

+ 265 more from Emerging Threats Open → showing the 10 highest-severity

SigmaHQ/sigma

16 rules
Detection Severity Format
Antivirus - Ransomware Signature Critical Sigma
LockerGoga Ransomware Activity Critical Sigma
Potential Conti Ransomware Activity Critical Sigma
WannaCry Ransomware Activity Critical Sigma
AWS KMS Imported Key Material Usage High Sigma
BlueSky Ransomware Artefacts High Sigma
FunkLocker Ransomware File Creation High Sigma
Load Of RstrtMgr.DLL By A Suspicious Process High Sigma
Renamed Gpg.EXE Execution High Sigma
Suspicious Reg Add BitLocker High Sigma

+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

15 rules
Detection Severity Format
Excessive AWS S3 Object Encryption with SSE-C High Elastic TOML
Potential Ransomware Note File Dropped via SMB High Elastic TOML
Ransomware - Detected - Elastic Defend High Elastic TOML
Ransomware - Prevented - Elastic Defend High Elastic TOML
Suspicious File Renamed via SMB High Elastic TOML
Unusual AWS S3 Object Encryption with SSE-C High Elastic TOML
AWS S3 Object Encryption Using External KMS Key Medium Elastic TOML
Deprecated - M365 Security Compliance Potential Ransomware Activity Medium Elastic TOML
Potential AWS S3 Bucket Ransomware Note Uploaded Medium Elastic TOML
Potential Linux Ransomware Note Creation Detected Medium Elastic TOML

+ 5 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

14 rules
Detection Severity Format
Slack Potentially Malicious File Shared Critical Panther Python
AWS S3 Object Exfiltration WITH Object Deletion High Panther Python
Azure Storage Blob CPK Encryption Detected High Panther Python
Azure Storage Blob Upload WITH CPK Encryption Error High Panther Python
GCP GCS Ransom Note Upload High Panther Python
S3 Object Encrypted with External KMS Key High Panther Python
AppOmni Alert Passthrough Medium Panther Python
AWS EC2 EBS Encryption Disabled Medium Panther Python
AWS S3 Object Copied to External Account Bucket Medium Panther Python
GCP GCS Bulk Object Rewrite Operation Medium Panther Python

+ 4 more from panther-labs/panther-analysis → showing the 10 highest-severity

socfortress/Wazuh-Rules

10 rules
Detection Severity Format
File encryption using 7z with password (T1486) High Wazuh XML
File encryption using ccencrypt and password (T1486) High Wazuh XML
File encryption using GPG and AES-256 (T1486) High Wazuh XML
File encryption using OpenSSL rsautl with RSA public key (T1486) High Wazuh XML
Suspicious file encryption detected using gpg (T1027.009) High Wazuh XML
Sysmon - Event 1: Process creation · DiskCryptor Execution (T1486) High Wazuh XML
Sysmon - Event 1: Process creation · GPG4Win File Encryption (T1486) High Wazuh XML
Potential file encryption activity using 7z with password (T1022.001) Medium Wazuh XML
Suspicious encryption activity detected: use of ccencrypt binary (possible ransomware behavior). Medium Wazuh XML
Suspicious OpenSSL encryption or key generation activity detected (MITRE T1486) Medium Wazuh XML

splunk/security_content

10 rules
Detection Severity Format
ASL AWS Detect Users creating keys with encrypt policy without MFA Undefined SPL
AWS Detect Users creating keys with encrypt policy without MFA Undefined SPL
AWS Detect Users with KMS keys performing encryption S3 Undefined SPL
High Process Termination Frequency Undefined SPL
Ransomware Notes bulk creation Undefined SPL
Ryuk Test Files Detected Undefined SPL
Samsam Test File Write Undefined SPL
Windows BitLocker Suspicious Command Usage Undefined SPL
Windows DiskCryptor Usage Undefined SPL
Windows .Key File Creation in Root Directory Undefined SPL

Azure/Azure-Sentinel

6 rules
Detection Severity Format
AV detections related to Dev-0530 actors High KQL
AV detections related to Europium actors High KQL
AV detections related to Hive Ransomware High KQL
Dev-0530 File Extension Rename High KQL
ARS Ransomware Event triggered Undefined KQL
LockBit and related tool hash IoCs Undefined KQL

elastic/protections-artifacts

6 rules
Detection Severity Format
DARKRADIATION Ransomware Infection Undefined Elastic TOML
Inhibit System Recovery Followed by a Suspicious File Rename Undefined Elastic TOML
Suspicious File Rename by an Unusual Process Undefined Elastic TOML
Suspicious File Rename from Unbacked Memory Undefined Elastic TOML
Suspicious File Rename via SMB Undefined Elastic TOML
VSS Service Disabled Followed by a Suspicious File Rename Undefined Elastic TOML

Bert-JanP/Hunting-Queries-Detection-Rules

5 rules
Detection Severity Format
ASR Ransomware Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Monitor ransomwarelive for companies of interest on ransowmare data leak sites (DLS) Undefined KQL
RansomwareDoubleExtention Undefined KQL
Triggers when a known ransomware extension has been found Undefined KQL

Wazuh Core Ruleset

2 rules
Detection Severity Format
MS Graph message: Indicators that the system is infected with ransomware have been detected. Requires immediate action. Critical Wazuh XML
MS Graph Message: Indicators that the system is potentially affected by ransomware have been detected. Check the system for signs of infection. High Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.