Data Destruction
Description
Adversaries may perform data destruction over the course of an operation. The adversary may drop or create malware, tools, or other non-native files on a target system to accomplish this, potentially leaving behind traces of malicious activities. Such non-native files and other data may be removed over the course of an intrusion to maintain a small footprint or as a standard part of the post-intrusion cleanup process. (Citation: Enterprise ATT&CK January 2018) Data destruction may also be used to render operator interfaces unable to respond and to disrupt response functions from occurring as expected. An adversary may also destroy data backups that are vital to recovery after an incident. Standard file deletion commands are available on most operating system and device interfaces to perform cleanup, but adversaries may use other tools as well. Two examples are Windows Sysinternals SDelete and Active@ Killdisk.
Mapped SPARTA techniques
2 techniques
T0809 'Data Destruction' is the ATT&CK ICS technique for destroying data on systems; SPARTA EX-0010.02 'Wiper Malware' is the same activity (destroy data permanently). Cross-tactic moderate (T0809 sits in inhibit-response-function while SPARTA EX-0010.02 is execution); exact concept match.
T0809 'Data Destruction' addresses adversary destruction of data; SPARTA IMP-0005 'Destruction' includes destruction of mission data (recorder contents, telemetry archives, payload products) as one mode. Cross-tactic moderate (T0809 in inhibit-response-function vs SPARTA IMP-0005 impact); complementary to T0879's primary property-damage anchor.
Cite as SafeMode Space, mitre-attack-ics T0809.