Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0316 — Detection Strategy for Disk Content Wipe via Direct Access and Overwrite
DET0316

Detection Strategy for Disk Content Wipe via Direct Access and Overwrite

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0882 Analytic 0882
Windows

Processes attempting raw disk access via \\.\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window.

WinEventLog:Security EventCode=4673 WinEventLog:Sysmon Raw disk writes targeting \\.\PhysicalDrive* or MBR locations WinEventLog:Sysmon EventCode=6
[ProcessWhitelist] Backup, forensics, or imaging tools may perform legitimate raw disk access — requires tuning per environment.
[TimeWindow] Correlation threshold for process execution, driver load, and raw disk writes.
AN0883 Analytic 0883
Linux

Execution of destructive utilities (dd, shred, wipe) targeting block devices, or processes invoking syscalls to directly overwrite /dev/sd* or /dev/nvme* partitions. Correlate abnormal file write attempts with shell process execution and block device access.

auditd:SYSCALL open/write syscalls to block devices (/dev/sd*, /dev/nvme*) auditd:EXECVE Execution of dd, shred, or wipe with arguments targeting block devices
[TargetDevices] Exclude removable drives or designated partitions that may be overwritten during maintenance.
[EntropyThreshold] Tune detection for pseudorandom write patterns to reduce false positives during high-volume I/O.
AN0884 Analytic 0884
macOS

Abnormal invocation of diskutil or asr with destructive flags (eraseDisk, zeroDisk), or low-level IOKit calls that overwrite raw disk content. Detect correlation between elevated process execution and disk erase operations.

macos:unifiedlog diskutil eraseDisk/zeroDisk or asr restore with destructive flags macos:unifiedlog IOKit raw disk write activity targeting physical devices
[AdminToolWhitelist] Provisioning workflows may legitimately use diskutil/asr — whitelist by user or system context.
AN0885 Analytic 0885
Network Devices

Execution of CLI commands erasing file systems or storage (erase flash:, format disk, erase nvram:). Detect authentication events followed by destructive commands within the same privileged session.

networkdevice:cli erase flash:, erase nvram:, format disk networkdevice:syslog Privileged login followed by destructive command sequence
[PrivilegedUsers] Tune to exclude approved maintenance performed by authorized administrators.
[CommandPatterns] Expand or narrow destructive command coverage depending on vendor-specific syntax.

Detected Techniques

1

Details

MITRE ID
DET0316
STIX ID
x-mitre-detection-strategy--3a016ed2-47e0-414b-b90e-a44d1437354e
Analytics
4
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.