Adversaries may perform data destruction over the course of an operation. The adversary may drop or create malware, tools, or other non-native files on a target system to accomplish this, potentially leaving behind traces of malicious activities. Such non-native files and other data may be removed over the course of an intrusion to maintain a small footprint or as a standard part of the post-intrusion cleanup process. (Citation: Enterprise ATT&CK January 2018) Data destruction may also be used to render operator interfaces unable to respond and to disrupt response functions from occurring as expected. An adversary may also destroy data backups that are vital to recovery after an incident. Standard file deletion commands are available on most operating system and device interfaces to perform cleanup, but adversaries may use other tools as well. Two examples are Windows Sysinternals SDelete and Active@ Killdisk.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Remote Terminal Unit (RTU)
is related to Routers
is related to Firewall
is related to Control Server
is related to Application Server
is related to Virtual Private Network (VPN) Server
is related to Programmable Automation Controller (PAC)
is related to Safety Controller
is related to Distributed Control System (DCS) Controller
is related to Workstation
is related to Data Gateway
is related to Field I/O
is related to Jump Host
is related to Switch
is related to Programmable Logic Controller (PLC)
is related to Human-Machine Interface (HMI)
is related to Data Historian
is related to Intelligent Electronic Device (IED)
is blocked by Detection of Data Destruction
is blocked by Restrict File and Directory Permissions
is blocked by Data Backup
is blocked by Privileged Account Management
Impressum German English