Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1486

T1486Data Encrypted for Impact

T1486 — Data Encrypted for Impact is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 15 detection use cases covering it and 100 threat-intel articles citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
100Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Ransomware-style mass file rename / extension change Internal actions · alerting DSP ASL AWS Detect Users creating keys with encrypt policy without MFA ESCU actions · alerting P AWS Detect Users creating keys with encrypt policy without MFA ESCU actions · alerting P AWS Detect Users with KMS keys performing encryption S3 ESCU actions · hunting P High Process Termination Frequency ESCU actions · hunting P Ransomware Notes bulk creation ESCU actions · hunting P Ryuk Test Files Detected ESCU actions · alerting P Samsam Test File Write ESCU actions · alerting P Windows .Key File Creation in Root Directory ESCU actions · hunting P Windows BitLocker Suspicious Command Usage ESCU actions · alerting P Windows DiskCryptor Usage ESCU actions · hunting P [LLM] BitLocker tamper attempt via manage-bde or BitLocker PowerShell after WinRE shell access Bespoke actions · alerting DSΣPDDCS [LLM] Qilin Linux ransomware ELF payload (CVE-2026-50751 campaign) — known MD5 file event Bespoke install · hunting DSΣPDDCS [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk Bespoke actions · alerting DSΣPDDCS [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in temp Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (100)