Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0137 — Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands
DET0137

Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0384 Analytic 0384
Windows

Unusual direct disk access attempts (e.g., use of \\.\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads.

WinEventLog:Security EventCode=4673 WinEventLog:Sysmon Raw disk write access via \\.\PhysicalDrive* or \\.\C: WinEventLog:Sysmon EventCode=6
[ProcessWhitelist] Legitimate disk imaging or backup tools may trigger raw disk access — must be excluded per environment.
[TimeWindow] Correlate disk access, driver load, and process execution within a short timeframe to minimize false positives.
AN0385 Analytic 0385
Linux

Processes invoking destructive commands (dd, shred, wipe) with raw device targets (e.g., /dev/sda, /dev/nvme0n1). Detect direct writes to disk partitions and abnormal superblock or bootloader modifications. Correlate shell execution with subsequent block device I/O.

auditd:SYSCALL open/write syscalls on /dev/sd* or /dev/nvme* auditd:EXECVE Execution of dd, shred, wipe targeting block devices
[TargetDevices] Tune to exclude removable drives or test partitions commonly written by administrators.
[EntropyThreshold] Detects large blocks of pseudorandom data being written; may need tuning for backup/crypto workloads.
AN0386 Analytic 0386
macOS

Abnormal invocation of diskutil, asr, or low-level APIs (IOKit) to erase/partition drives. Correlate process execution with unified log entries showing destructive disk operations.

macos:unifiedlog diskutil eraseDisk / asr restore with destructive flags macos:unifiedlog IOKit disk write calls targeting raw devices
[AdminToolWhitelist] System administrators may legitimately use diskutil/asr for provisioning — whitelist by user or context.
AN0387 Analytic 0387
Network Devices

Execution of destructive CLI commands such as 'erase startup-config', 'erase flash:' or 'format disk' on routers/switches. Detect privilege level escalation preceding destructive commands.

networkdevice:cli erase flash:, erase startup-config, format disk networkdevice:syslog User privilege escalation to level 15/root prior to destructive commands
[PrivilegedUsers] Tune to exclude approved maintenance sessions by known administrators.
[CommandPatterns] Adjust monitored destructive command list depending on device vendor and OS.

Detected Techniques

1

Details

MITRE ID
DET0137
STIX ID
x-mitre-detection-strategy--da01afef-b769-4d31-964d-901fabaf6a8f
Analytics
4
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.