{"id":"T1561","name":"Disk Wipe","url":"https://attack.mitre.org/techniques/T1561","tactics":["impact"],"platforms":["Linux","macOS","Windows","Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0137","stix_id":"x-mitre-detection-strategy--da01afef-b769-4d31-964d-901fabaf6a8f","name":"Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands","url":"https://attack.mitre.org/detectionstrategies/DET0137","analytics":[{"id":"AN0384","stix_id":"x-mitre-analytic--5dc85538-115c-4c56-878a-39caaba91e74","name":"Analytic 0384","description":"Unusual direct disk access attempts (e.g., use of \\\\.\\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads.","url":"https://attack.mitre.org/detectionstrategies/DET0137#AN0384","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4673","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"Raw disk write access via \\\\.\\PhysicalDrive* or \\\\.\\C:","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ProcessWhitelist","description":"Legitimate disk imaging or backup tools may trigger raw disk access — must be excluded per environment."},{"field":"TimeWindow","description":"Correlate disk access, driver load, and process execution within a short timeframe to minimize false positives."}],"live":true,"detection_strategies":["DET0137"],"techniques":["T1561"]},{"id":"AN0385","stix_id":"x-mitre-analytic--d442d480-cfb9-43cc-b959-2f81513b432d","name":"Analytic 0385","description":"Processes invoking destructive commands (dd, shred, wipe) with raw device targets (e.g., /dev/sda, /dev/nvme0n1). Detect direct writes to disk partitions and abnormal superblock or bootloader modifications. Correlate shell execution with subsequent block device I/O.","url":"https://attack.mitre.org/detectionstrategies/DET0137#AN0385","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/write syscalls on /dev/sd* or /dev/nvme*","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"Execution of dd, shred, wipe targeting block devices","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"TargetDevices","description":"Tune to exclude removable drives or test partitions commonly written by administrators."},{"field":"EntropyThreshold","description":"Detects large blocks of pseudorandom data being written; may need tuning for backup/crypto workloads."}],"live":true,"detection_strategies":["DET0137"],"techniques":["T1561"]},{"id":"AN0386","stix_id":"x-mitre-analytic--2016853a-07eb-4df4-a471-69b55f82b34d","name":"Analytic 0386","description":"Abnormal invocation of diskutil, asr, or low-level APIs (IOKit) to erase/partition drives. Correlate process execution with unified log entries showing destructive disk operations.","url":"https://attack.mitre.org/detectionstrategies/DET0137#AN0386","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"diskutil eraseDisk / asr restore with destructive flags","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"IOKit disk write calls targeting raw devices","data_component":"DC0046","data_component_name":"Drive Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AdminToolWhitelist","description":"System administrators may legitimately use diskutil/asr for provisioning — whitelist by user or context."}],"live":true,"detection_strategies":["DET0137"],"techniques":["T1561"]},{"id":"AN0387","stix_id":"x-mitre-analytic--8faa753d-ec3f-4694-9a33-03ce4ccb722f","name":"Analytic 0387","description":"Execution of destructive CLI commands such as 'erase startup-config', 'erase flash:' or 'format disk' on routers/switches. Detect privilege level escalation preceding destructive commands.","url":"https://attack.mitre.org/detectionstrategies/DET0137#AN0387","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"erase flash:, erase startup-config, format disk","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-cli"},{"name":"networkdevice:syslog","channel":"User privilege escalation to level 15/root prior to destructive commands","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"PrivilegedUsers","description":"Tune to exclude approved maintenance sessions by known administrators."},{"field":"CommandPatterns","description":"Adjust monitored destructive command list depending on device vendor and OS."}],"live":true,"detection_strategies":["DET0137"],"techniques":["T1561"]}],"live":true,"version":"1.0","techniques":["T1561"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}