Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1486

T1486Data Encrypted for Impact

T1486 — Data Encrypted for Impact is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 16 detection use cases covering it and 401 threat-intel articles citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
401Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

Ransomware-style mass file rename / extension change Internal actions · alerting DSP ASL AWS Detect Users creating keys with encrypt policy without MFA ESCU actions · alerting P AWS Detect Users creating keys with encrypt policy without MFA ESCU actions · alerting P AWS Detect Users with KMS keys performing encryption S3 ESCU actions · hunting P High Process Termination Frequency ESCU actions · hunting P Ransomware Notes bulk creation ESCU actions · hunting P Ryuk Test Files Detected ESCU actions · alerting P Samsam Test File Write ESCU actions · alerting P Windows .Key File Creation in Root Directory ESCU actions · hunting P Windows BitLocker Suspicious Command Usage ESCU actions · alerting P Windows DiskCryptor Usage ESCU actions · hunting P [LLM] Babuk-derived .babyk ransomware encryption on ESXi hosts Bespoke actions · alerting DSΣPDDCS [LLM] LockBit payload execution via PsExec service (PsExecSvc.exe → 1.exe/LBB.exe) Bespoke actions · alerting DSΣPDDCS [LLM] Mass .SINOBI file-extension writes indicating domain-wide encryption Bespoke actions · alerting DSΣDDCS [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk Bespoke actions · alerting DSΣPDDCS [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in temp Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (401)