kevmap

TechniquesT1486 › AN0603

AN0603 Analytic 0603

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops.</p>
Detects
T1486 Data Encrypted for Impact
Part of
DET0215 Detection of Multi-Platform File Encryption for Impact

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLopenat, write, rename, unlinkDC0061 File Modification
auditd:SYSCALLexecveDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
FilenamePatternLook for creation of ransom note files (e.g., READ_ME.txt, HELP_DECRYPT.html).
SyscallBurstRateHigh write/open/unlink activity in short intervals indicates encryption attempts.
DirectoryTargetedCorrelate activity in /home, /etc, /opt, or mounted volumes.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2023-38831RARLAB WinRARMapped