MITRE ATT&CK ICS
T0809

Data Destruction

Description

Adversaries may perform data destruction over the course of an operation. The adversary may drop or create malware, tools, or other non-native files on a target system to accomplish this, potentially leaving behind traces of malicious activities. Such non-native files and other data may be removed over the course of an intrusion to maintain a small footprint or as a standard part of the post-intrusion cleanup process. (Citation: Enterprise ATT&CK January 2018) Data destruction may also be used to render operator interfaces unable to respond and to disrupt response functions from occurring as expected. An adversary may also destroy data backups that are vital to recovery after an incident. Standard file deletion commands are available on most operating system and device interfaces to perform cleanup, but adversaries may use other tools as well. Two examples are Windows Sysinternals SDelete and Active@ Killdisk.

Mapped SPARTA techniques

2 techniques

  • EX-0010.02Wiper MalwareST0004
    addresses
    moderate

    T0809 'Data Destruction' is the ATT&CK ICS technique for destroying data on systems; SPARTA EX-0010.02 'Wiper Malware' is the same activity (destroy data permanently). Cross-tactic moderate (T0809 sits in inhibit-response-function while SPARTA EX-0010.02 is execution); exact concept match.

  • IMP-0005DestructionST0009
    addresses
    moderate

    T0809 'Data Destruction' addresses adversary destruction of data; SPARTA IMP-0005 'Destruction' includes destruction of mission data (recorder contents, telemetry archives, payload products) as one mode. Cross-tactic moderate (T0809 in inhibit-response-function vs SPARTA IMP-0005 impact); complementary to T0879's primary property-damage anchor.

Cite as SafeMode Space, mitre-attack-ics T0809.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.