Data Destruction T1485

Tactic: Impact

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as del and rm often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Events covered

20 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 194 rules share fields, values, and exclusions.

Fields filtered most (202 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType35eq 28, in 8, starts_with 1, wildcard 1creation, exec, ModifyDBInstance, rename, DeleteDBClusterSnapshot
data_stream.dataset31eq 31aws.cloudtrail, azure.activitylogs, github.audit, gcp.audit, network_traffic.amqp
operationName26eq 25, in 1microsoft.storage/storageaccounts/blobservices/write, deleteblob, microsoft.compute/disks/delete, microsoft.compute/restorepointcollections/delete, microsoft.compute/snapshots/delete
event.outcome20eq 20success
aws::eventName18eq 12, in 5, ne 1, starts_with 1PutBucketVersioning, PutBucketLogging, putbucketlifecycle, CreateKey, DeleteBucket
resultType18in 18Succeeded, Success
TargetFilename17starts_with 9, in 6, wildcard 2, contains 1, ends_with 1c:\users\, /etc/ssl/certs/, *.7z, *.backup*, *.bak
sourcetype17eq 17, in 4o365:management:activity, ms:o365:reporting:messagetrace, o365:reporting:messagetrace, auditd, httpevent
CommandLine16contains 14, in 3, ends_with 1, match 1, wildcard 1-r, -s, -k gpsvcgroup, -q, of=
Provider_Name16eq 15, in 1rds.amazonaws.com, kms.amazonaws.com, logs.amazonaws.com, s3.amazonaws.com, account.amazonaws.com
EventID14eq 11, in 323, 26, 4688, 1, DestroyCryptoKeyVersion
aws::eventSource13eq 13s3.amazonaws.com, rds.amazonaws.com, bedrock.amazonaws.com, eks.amazonaws.com, elasticfilesystem.amazonaws.com
process_name11eq 9, regex_match 2rm, (?i)\x5ccipher\.exe, shred, dd, gw-audit
event_action10eq 7, in 3deleted, created, modified
Image9ends_with 4, is_not_null 3, eq 1, starts_with 1/bin/dd, /dd, /rm, /shred, /usr/bin/dd

Top indicator values (699 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
20369
resultTypein
Succeeded
1851
resultTypein
Success
1851
data_stream.dataseteq
aws.cloudtrail
15169
data_stream.dataseteq
azure.activitylogs
739
data_stream.dataseteq
github.audit
418
event_actioneq
deleted
78
Workloadeq
exchange
620
aws::eventSourceeq
s3.amazonaws.com
617
aws::eventSourceeq
rds.amazonaws.com
323
sourcetypeeq
o365:management:activity
680
CommandLinecontains
-r
513
CommandLinecontains
-s
410
EventTypeeq
creation
458
Operationeq
harddelete
44
m365::Folder.Pathin
\\recoverable items\\deletions
44
m365::Folder.Pathin
\\sent items
44
process_ideq
4
419
sourcetypein
ms:o365:reporting:messagetrace
44
sourcetypein
o365:reporting:messagetrace
44
EventIDeq
4688
3317
EventIDin
23
310
EventIDin
26
310
OriginalFileNameeq
sdelete.exe
34
Provider_Nameeq
rds.amazonaws.com
39
TargetFilenamestarts_with
c:\users\
313
aws::eventNameeq
PutBucketVersioning
33
event.typeeq
change
394
event_actionin
created
37
event_actionin
modified
37

Exclusions (264 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinecontains
sdelete
2
CommandLinecontains
-c
1
CommandLinecontains
-h
1
CommandLinecontains
-z
1
CommandLinecontains
/?
1
aws::sourceIPAddresseq
backup.amazonaws.com
2
aws::userAgenteq
aws internal
2
process.code_signature.trustedeq
true
2
Imageends_with
\sdelete.exe
1
Imageends_with
\sdelete64.exe
1
Imageends_with
\sdelete64a.exe
1
Imageeq
?:\program files\tortoisesvn\bin\tsvncache.exe
1
Imageeq
?:\windows\system32\svchost.exe
1
Imageeq
c:\prowin22\32bit\proseriesbackgroundupdater.exe
1
Imageeq
c:\windows\system32\msiexec.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 21 rules

Elastic 46 rules

Splunk 40 rules

Kusto 39 rules

YARA-L 7 rules

Panther 41 rules