Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1485

T1485Data Destruction

T1485 — Data Destruction is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 74 detection use cases covering it and 21 threat-intel articles citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
74Use cases
21Articles
1Sub-techniques
1Tactic

Sub-techniques (1)

Use cases covering this technique (74)

AWS ECS cluster deleted Internal actions · alerting DDCW AWS KMS key deleted or scheduled for deletion Internal actions · alerting DDCW AWS RDS DB cluster deleted Internal actions · alerting DDCW Azure storage soft-delete disabled Internal actions · alerting DD GitHub mass repository deletion Internal actions · alerting DD MongoDB database dropped Internal actions · alerting DD PostgreSQL database dropped Internal actions · alerting DD AWS Bedrock Delete Knowledge Base ESCU actions · alerting P GitHub Enterprise Remove Organization ESCU actions · hunting P GitHub Enterprise Repository Archived ESCU actions · hunting P GitHub Enterprise Repository Deleted ESCU actions · hunting P GitHub Organizations Repository Archived ESCU actions · hunting P GitHub Organizations Repository Deleted ESCU actions · hunting P O365 Email Hard Delete Excessive Volume ESCU actions · hunting P O365 Email Password and Payroll Compromise Behavior ESCU actions · alerting P O365 Email Receive and Hard Delete Takeover Behavior ESCU actions · hunting P O365 Email Send and Hard Delete Exfiltration Behavior ESCU actions · hunting P O365 Email Send and Hard Delete Suspicious Behavior ESCU actions · hunting P O365 Email Send Attachments Excessive Volume ESCU actions · hunting P Common Ransomware Extensions ESCU actions · alerting P Common Ransomware Notes ESCU actions · hunting P Excessive File Deletion In WinDefender Folder ESCU actions · alerting P Linux Account Manipulation Of SSH Config and Keys ESCU actions · hunting P Linux Auditd Data Destruction Command ESCU actions · alerting P Linux Auditd Dd File Overwrite ESCU actions · alerting P Linux Auditd Shred Overwrite Command ESCU actions · alerting P Linux Data Destruction Command ESCU actions · alerting P Linux DD File Overwrite ESCU actions · alerting P Linux Deleting Critical Directory Using RM Command ESCU actions · alerting P Linux Deletion Of Cron Jobs ESCU actions · hunting P Linux Deletion Of Init Daemon Script ESCU actions · alerting P Linux Deletion Of Services ESCU actions · alerting P Linux Deletion of SSL Certificate ESCU actions · hunting P Linux High Frequency Of File Deletion In Boot Folder ESCU actions · alerting P Linux High Frequency Of File Deletion In Etc Folder ESCU actions · hunting P Linux Shred Overwrite Command ESCU actions · alerting P Sdelete Application Execution ESCU actions · alerting P Windows Data Destruction Recursive Exec Files Deletion ESCU actions · alerting P Windows Disable Memory Crash Dump ESCU actions · alerting P Windows File Without Extension In Critical Folder ESCU actions · alerting P Windows High File Deletion Frequency ESCU actions · hunting P Detect DNS Query to Decommissioned S3 Bucket ESCU actions · hunting P Detect Web Access to Decommissioned S3 Bucket ESCU actions · hunting P [LLM] WebDAV MOVE/COPY write-verb succeeds against goshs artifact server (Overwrite:T destination clobber) Bespoke exploit · hunting SΣP [LLM] goshs process deletes or renames served files while launched with --no-delete (impact confirmation) Bespoke actions · alerting DSΣPDDCS [LLM] LightRAG destructive document ops post-bypass (DELETE /documents, clear_cache, unauth upload) Bespoke actions · alerting SΣP [LLM] LightRAG CVE-2026-61736: cross-origin DELETE of document store (destructive CORS abuse) Bespoke actions · alerting SP [LLM] n8n-MCP destructive workflow version backup deletion (delete/prune/truncate) — CVE-2026-54052 impact Bespoke actions · alerting SΣP [LLM] Sha1-Hulud destructive wiper fallback (cipher /W, recursive del, shred over home dir) Bespoke actions · alerting DSΣPDDCS [LLM] YesWiki unauthenticated erasespamedcomments page-deletion invocation (CVE-2026-52766) Bespoke exploit · alerting SΣP [LLM] YesWiki confirmed mass page deletion — bulk 'Suppression de la page' / deletion-request burst (CVE-2026-52766) Bespoke actions · alerting SP [LLM] YesWiki page-deletion aftermath — 404 spike on previously-valid wiki pages (CVE-2026-52766) Bespoke actions · hunting SP [LLM] 9router database overwrite via POST /api/settings/database (CVE-2026-55500) Bespoke actions · alerting SΣP [LLM] Mass graph destruction via unbounded DETACH DELETE in Neo4j query.log Bespoke actions · alerting SΣPDD [LLM] CVE-2026-50027 unauthenticated destructive delete via /api/documents/remove-by-tags Bespoke actions · alerting SΣP [LLM] CVE-2026-50027 full exploit chain: probe, write, bulk-read, delete from one source in 15m Bespoke actions · alerting SP [LLM] GCS bucket deletion of a logging-sink / data-stream destination (bucket-hijack precursor) Bespoke actions · hunting ΣPDD [LLM] AWS S3 DeleteBucket on a replication / log-delivery destination (bucket-hijack precursor) Bespoke actions · hunting ΣPDDCW [LLM] AWS S3 bucket DeleteBucket then CreateBucket of the SAME name across accounts (hijack signature) Bespoke actions · alerting PDDCW [LLM] Locale-conditional rm -rf wiper command from python/node runtime Bespoke actions · alerting DSΣPDDCS [LLM] AI coding agent bulk-deleting JUnit test files after jqwik resolution Bespoke actions · alerting DSPDDCS [LLM] Malicious privileged DaemonSet apply in kube-system (host-provisioner-iran / host-provisioner-std / kamikaze) Bespoke install · alerting DSΣPDDCS [LLM] Host-root mount wiper: chroot /mnt/host reboot -f or rm -rf / --no-preserve-root Bespoke actions · alerting DSΣPDDCS [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` Bespoke actions · alerting DSΣPDD [LLM] DynoWiper / ZOV wiper known-bad SHA-1 hash execution Bespoke install · alerting DSΣPDDCS [LLM] DynoWiper schtask.exe / *_update.exe execution from C:\inetpub\pub\ Bespoke install · alerting DSΣPDDCS [LLM] Mass file-content overwrite by single non-system process from non-standard path Bespoke actions · hunting DSPDDCS [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) Bespoke install · alerting DSΣP [LLM] DynoWiper PDB-string + vagrant build artefact in loaded modules Bespoke install · hunting DSΣP [LLM] SHA1-Hulud wiper: mass deletion of user home directory by npm/node descendant Bespoke actions · alerting DSPDDCS [LLM] node-ipc destructive wiper component ssl-geospec.js written under node_modules\node-ipc\dao Bespoke install · alerting DSΣPDDCS [LLM] peacenotwar payload: creation of WITH-LOVE-FROM-AMERICA.txt protest file Bespoke actions · alerting DSΣPDDCS [LLM] node-ipc destructive payload artifact (dao/ssl-geospec.js) on disk Bespoke install · alerting DSΣPDDCS [LLM] Mass file overwrite by Node runtime (node-ipc heart-emoji data destruction) Bespoke actions · hunting DSPDDCS

Articles citing this technique (21)