1200KM / detection
T1561 Disk Wipe — Detection Rules
Detection workspace for T1561 Disk Wipe: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0137 Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands
AN0384 Analytic 0384
Unusual direct disk access attempts (e.g., use of \\.\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads.
AN0385 Analytic 0385
Processes invoking destructive commands (dd, shred, wipe) with raw device targets (e.g., /dev/sda, /dev/nvme0n1). Detect direct writes to disk partitions and abnormal superblock or bootloader modifications. Correlate shell execution with subsequent block device I/O.
AN0386 Analytic 0386
Abnormal invocation of diskutil, asr, or low-level APIs (IOKit) to erase/partition drives. Correlate process execution with unified log entries showing destructive disk operations.
AN0387 Analytic 0387
Execution of destructive CLI commands such as 'erase startup-config', 'erase flash:' or 'format disk' on routers/switches. Detect privilege level escalation preceding destructive commands.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- Drive Access · DC0054
- Drive Modification · DC0046
- Driver Load · DC0079
- Process Creation · DC0032
- User Account Authentication · DC0002
- User Account Metadata · DC0013
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.