EXPLORE
← Back to Explore
T1486

Data Encrypted for Impact

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key ...

ESXiIaaSLinuxmacOSWindows
394
Detections
5
Sources
19
Threat Actors

BY SOURCE

355sublime15elastic11sigma10splunk_escu3kql

PROCEDURES (90)

Authentication Monitoring68 detections

Auto-extracted: 68 detections for authentication monitoring

General Monitoring34 detections

Auto-extracted: 34 detections for general monitoring

Attachment29 detections

Auto-extracted: 29 detections for attachment

Email Security18 detections

Auto-extracted: 18 detections for email security

Script Execution Monitoring14 detections

Auto-extracted: 14 detections for script execution monitoring

Phish8 detections

Auto-extracted: 8 detections for phish

Network Connection Monitoring8 detections

Auto-extracted: 8 detections for network connection monitoring

Email8 detections

Auto-extracted: 8 detections for email

Download7 detections

Auto-extracted: 7 detections for download

Email7 detections

Auto-extracted: 7 detections for email

Bypass7 detections

Auto-extracted: 7 detections for bypass

Base647 detections

Auto-extracted: 7 detections for base64

Aws6 detections

Auto-extracted: 6 detections for aws

Suspicious5 detections

Auto-extracted: 5 detections for suspicious

Suspicious5 detections

Auto-extracted: 5 detections for suspicious

Suspicious5 detections

Auto-extracted: 5 detections for suspicious

Impersonat5 detections

Auto-extracted: 5 detections for impersonat

Download5 detections

Auto-extracted: 5 detections for download

Macro5 detections

Auto-extracted: 5 detections for macro

Service4 detections

Auto-extracted: 4 detections for service

Obfuscat4 detections

Auto-extracted: 4 detections for obfuscat

Ransomware4 detections

Auto-extracted: 4 detections for ransomware

Office4 detections

Auto-extracted: 4 detections for office

Ransomware3 detections

Auto-extracted: 3 detections for ransomware

Encrypt3 detections

Auto-extracted: 3 detections for encrypt

Suspicious3 detections

Auto-extracted: 3 detections for suspicious

Bypass3 detections

Auto-extracted: 3 detections for bypass

Attachment3 detections

Auto-extracted: 3 detections for attachment

Impersonat3 detections

Auto-extracted: 3 detections for impersonat

Unusual3 detections

Auto-extracted: 3 detections for unusual

Phish3 detections

Auto-extracted: 3 detections for phish

Remote3 detections

Auto-extracted: 3 detections for remote

Phish3 detections

Auto-extracted: 3 detections for phish

Attachment3 detections

Auto-extracted: 3 detections for attachment

Http3 detections

Auto-extracted: 3 detections for http

Office3 detections

Auto-extracted: 3 detections for office

Encrypt3 detections

Auto-extracted: 3 detections for encrypt

Impersonat2 detections

Auto-extracted: 2 detections for impersonat

Credential2 detections

Auto-extracted: 2 detections for credential

Cloud2 detections

Auto-extracted: 2 detections for cloud

Base642 detections

Auto-extracted: 2 detections for base64

Ransomware2 detections

Auto-extracted: 2 detections for ransomware

Attachment2 detections

Auto-extracted: 2 detections for attachment

Powershell2 detections

Auto-extracted: 2 detections for powershell

Ransomware2 detections

Auto-extracted: 2 detections for ransomware

Obfuscat2 detections

Auto-extracted: 2 detections for obfuscat

Service2 detections

Auto-extracted: 2 detections for service

Service2 detections

Auto-extracted: 2 detections for service

Service2 detections

Auto-extracted: 2 detections for service

Credential2 detections

Auto-extracted: 2 detections for credential

Credential2 detections

Auto-extracted: 2 detections for credential

Macro2 detections

Auto-extracted: 2 detections for macro

Api2 detections

Auto-extracted: 2 detections for api

Evasion2 detections

Auto-extracted: 2 detections for evasion

Remote2 detections

Auto-extracted: 2 detections for remote

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Macro1 detections

Auto-extracted: 1 detections for macro

Macro1 detections

Auto-extracted: 1 detections for macro

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Inject1 detections

Auto-extracted: 1 detections for inject

Obfuscat1 detections

Auto-extracted: 1 detections for obfuscat

Download1 detections

Auto-extracted: 1 detections for download

Credential1 detections

Auto-extracted: 1 detections for credential

Obfuscat1 detections

Auto-extracted: 1 detections for obfuscat

Credential1 detections

Auto-extracted: 1 detections for credential

Email1 detections

Auto-extracted: 1 detections for email

Credential1 detections

Auto-extracted: 1 detections for credential

Cloud1 detections

Auto-extracted: 1 detections for cloud

Api1 detections

Auto-extracted: 1 detections for api

Email1 detections

Auto-extracted: 1 detections for email

Base641 detections

Auto-extracted: 1 detections for base64

Inject1 detections

Auto-extracted: 1 detections for inject

Cloud1 detections

Auto-extracted: 1 detections for cloud

Office1 detections

Auto-extracted: 1 detections for office

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Impersonat1 detections

Auto-extracted: 1 detections for impersonat

Encrypt1 detections

Auto-extracted: 1 detections for encrypt

Download1 detections

Auto-extracted: 1 detections for download

Inject1 detections

Auto-extracted: 1 detections for inject

Http1 detections

Auto-extracted: 1 detections for http

Cloud1 detections

Auto-extracted: 1 detections for cloud

Phish1 detections

Auto-extracted: 1 detections for phish

Cloud1 detections

Auto-extracted: 1 detections for cloud

Remote1 detections

Auto-extracted: 1 detections for remote

Powershell1 detections

Auto-extracted: 1 detections for powershell

Email1 detections

Auto-extracted: 1 detections for email

Powershell1 detections

Auto-extracted: 1 detections for powershell

Service1 detections

Auto-extracted: 1 detections for service

DETECTIONS (394)

Adobe branded PDF file linking to a password-protected file from untrusted sender
sublimehigh
AnonymousFox indicators
sublimehigh
Anthropic Magic String in HTML
sublimelow
Antivirus - Ransomware Signature
sigmacritical
ASL AWS Detect Users creating keys with encrypt policy without MFA
splunk_escu
ASR Ransomware
kql
Attachment soliciting user to enable macros
sublimehigh
Attachment with auto-executing macro (unsolicited)
sublimemedium
Attachment with auto-opening VBA macro (unsolicited)
sublimemedium
Attachment with encrypted zip (unsolicited)
sublimemedium
Attachment with high risk VBA macro (unsolicited)
sublimehigh
Attachment with macro calling executable
sublimehigh
Attachment with suspicious author (unsolicited)
sublimehigh
Attachment with unscannable encrypted zip
sublimemedium
Attachment with VBA macros from employee impersonation (unsolicited)
sublimehigh
Attachment: .csproj with suspicious commands
sublimehigh
Attachment: 7z Archive Containing RAR File
sublimemedium
Attachment: Any .sap file (unsolicited)
sublimelow
Attachment: Any HTML file within archive (unsolicited)
sublimemedium
Attachment: Archive containing disallowed file type
sublimelow
Attachment: Archive contains DLL-loading macro
sublimehigh
Attachment: Archive with embedded CHM file
sublimemedium
Attachment: Archive with embedded EXE file
sublimehigh
Attachment: Archive with pdf, txt and wsf files
sublimemedium
Attachment: Base64 encoded bash command in filename
sublimehigh
Attachment: Calendar file with invisible Unicode characters
sublimehigh
Attachment: cmd file extension
sublimelow
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
sublimecritical
Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
sublimehigh
Attachment: DocX embedded binary
sublimehigh
Attachment: DOCX with hyperlink targeting recipient address
sublimemedium
Attachment: Double base64-encoded zip file in HTML smuggling attachment
sublimehigh
Attachment: EICAR string present
sublimelow
Attachment: Embedded Javascript in SVG file
sublimehigh
Attachment: Embedded VBScript in MHT file
sublimemedium
Attachment: EML file with HTML attachment (unsolicited)
sublimemedium
Attachment: EML with embedded Javascript in SVG file
sublimehigh
Attachment: EML with Encrypted ZIP
sublimelow
Attachment: EML with QR code redirecting to Cloudflare challenges
sublimelow
Attachment: Emotet heavily padded doc in zip file
sublimehigh
Attachment: Employment contract update with suspicious file naming
sublimehigh
Attachment: Encrypted Microsoft Office file (unsolicited)
sublimemedium
Attachment: Encrypted ZIP containing VHDX file
sublimemedium
Attachment: Encrypted zip file with payment-related lure
sublimemedium
Attachment: Excel Web Query File (IQY)
sublimehigh
Attachment: Fake attachment image lure
sublimemedium
Attachment: Fake PDF Invoices Yara
sublimemedium
Attachment: Fake Slack installer
sublimehigh
Attachment: Fake Zoom installer
sublimehigh
Attachment: File execution via Javascript
sublimemedium
Attachment: Filename containing Unicode braille pattern blank character
sublimehigh
Attachment: Filename containing Unicode right-to-left override character
sublimehigh
Attachment: HTML attachment with Javascript location
sublimehigh
Attachment: HTML file contains exclusively Javascript
sublimemedium
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
sublimehigh
Attachment: HTML file with excessive padding and suspicious patterns
sublimehigh
Attachment: HTML smuggling 'body onload' linking to suspicious destination
sublimehigh
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
sublimehigh
Attachment: HTML smuggling with atob and high entropy
sublimehigh
Attachment: HTML smuggling with atob and high entropy via calendar invite
sublimehigh
Attachment: HTML smuggling with auto-downloaded file
sublimehigh
Attachment: HTML smuggling with base64 encoded JavaScript function
sublimehigh
Attachment: HTML smuggling with base64 encoded ZIP file
sublimemedium
Attachment: HTML smuggling with concatenation obfuscation
sublimehigh
Attachment: HTML smuggling with decimal encoding
sublimehigh
Attachment: HTML smuggling with embedded base64 streamed file download
sublimehigh
Attachment: HTML smuggling with embedded base64-encoded executable
sublimehigh
Attachment: HTML smuggling with embedded base64-encoded ISO
sublimehigh
Attachment: HTML smuggling with eval and atob
sublimehigh
Attachment: HTML smuggling with eval and atob via calendar invite
sublimehigh
Attachment: HTML smuggling with excessive line break obfuscation
sublimehigh
Attachment: HTML smuggling with fromCharCode and other signals
sublimehigh
Attachment: HTML smuggling with hex strings
sublimemedium
Attachment: HTML smuggling with high entropy and other signals
sublimehigh
Attachment: HTML smuggling with raw array buffer
sublimehigh
Attachment: HTML smuggling with RC4 decryption
sublimehigh
Attachment: HTML smuggling with ROT13
sublimehigh
Attachment: HTML smuggling with setTimeout
sublimehigh
Attachment: HTML smuggling with unescape
sublimehigh
Attachment: ICS file with AWS Lambda URL
sublimemedium
Attachment: ICS file with excessive custom properties
sublimemedium
Attachment: ICS with embedded document
sublimelow
Attachment: ICS with embedded Javascript in SVG file
sublimehigh
Attachment: JavaScript file with suspicious base64-encoded executable
sublimehigh
Attachment: Legal themed message or PDF with suspicious indicators
sublimemedium
Attachment: LNK file
sublimehigh
Attachment: LNK with embedded content
sublimehigh
Attachment: Macro files containing MHT content
sublimemedium
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
sublimehigh
Attachment: Malformed OLE file
sublimehigh
Attachment: Malicious OneNote commands
sublimehigh
Attachment: Malicious zip file matching zipline campaign
sublimemedium
Attachment: Microsoft impersonation via PDF with link and suspicious language
sublimehigh
Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
sublimemedium
Attachment: MS OOXML file created by Administrator with zero edit time
sublimehigh
Attachment: MSI installer file
sublimemedium
Attachment: Office document loads remote document template
sublimemedium
Attachment: Office document with VSTO add-in
sublimehigh
Attachment: Office file with suspicious function calls or downloaded file path
sublimehigh
Attachment: OLE external relationship containing file scheme link to executable filetype
sublimehigh
Attachment: OLE external relationship containing file scheme link to IP address
sublimehigh
Attachment: Password-protected PDF with fake document indicators
sublimemedium
Attachment: PDF file with embedded content
sublimehigh
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
sublimemedium
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
sublimemedium
Attachment: PDF generated with wkhtmltopdf tool and default title
sublimelow
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
sublimemedium
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
sublimemedium
Attachment: PDF Object Hash with Blue File Icon
sublimemedium
Attachment: PDF templated investment lure
sublimemedium
Attachment: PDF with base64 JavaScript and eval functions
sublimemedium
Attachment: PDF with CVE-2026-34621 lures
sublimehigh
Attachment: PDF with embedded box-lure and javascript
sublimemedium
Attachment: PDF with embedded Javascript
sublimemedium
Attachment: PDF with JSFck obfuscation
sublimehigh
Attachment: PDF with link to DMG file download
sublimemedium
Attachment: PDF with link to zip containing a wsf file
sublimehigh
Attachment: PDF with localhost IP in EXIF title metadata
sublimemedium
Attachment: PDF with password in filename matching body text
sublimemedium
Attachment: PDF with quote lure
sublimemedium
Attachment: PDF with suspicious document view lure
sublimemedium
Attachment: PDF with suspicious HeadlessChrome metadata
sublimemedium
Attachment: PDF with suspicious language and redirect to suspicious file type
sublimehigh
Attachment: PDF with suspicious view document characteristics
sublimemedium
Attachment: Potential sandbox evasion in Office file
sublimehigh
Attachment: PowerPoint with suspicious hyperlink
sublimehigh
Attachment: PowerShell content
sublimehigh
Attachment: QR code with userinfo portion
sublimehigh
Attachment: QuickBooks PDF lure
sublimemedium
Attachment: RDP connection file
sublimemedium
Attachment: Risk assessment PDF with inline image
sublimehigh
Attachment: RTF with embedded content
sublimemedium
Attachment: Self-sender PDF with minimal content and view prompt
sublimehigh
Attachment: SFX archive containing commands
sublimemedium
Attachment: SVG file execution
sublimehigh
Attachment: SVG file with HTML entity encoded href attributes
sublimemedium
Attachment: SVG files with evasion elements
sublimehigh
Attachment: TAR file with RAR type
sublimehigh
Attachment: Uncommon compressed file
sublimelow
Attachment: Web files with suspicious comments
sublimehigh
Attachment: WinRAR CVE-2025-8088 exploitation
sublimehigh
Attachment: ZIP containing Office binary with embedded DLL
sublimemedium
Attachment: ZIP file with CVE-2026-0866 exploit
sublimemedium
Attachment: ZIP filename mismatch
sublimelow
AWS Detect Users creating keys with encrypt policy without MFA
splunk_escu
AWS Detect Users with KMS keys performing encryption S3
splunk_escu
AWS EC2 Disable EBS Encryption
sigmamedium
AWS KMS Imported Key Material Usage
sigmahigh
AWS S3 Object Encryption Using External KMS Key
elasticmedium
Brand impersonation: Google Drive fake file share
sublimemedium
Brand impersonation: Greetings Island
sublimehigh
Brand impersonation: Microsoft logo image linking to free file host
sublimehigh
Brand impersonation: Paperless Post
sublimehigh
Brand impersonation: Sharepoint fake file share
sublimemedium
Brand impersonation: Vanguard
sublimemedium
Brand impersonation: WeTransfer
sublimehigh
Brand impersonation: Zoom with deceptive link display
sublimemedium
Brand spoof: Dropbox
sublimemedium
Catbox.moe link from untrusted source
sublimemedium
ClickFix: Clipboard hijack lure with copy-paste-to-terminal instruction
sublimehigh
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
sublimecritical
Deprecated - M365 Security Compliance Potential Ransomware Activity
elasticmedium
Encrypted Microsoft Office files from untrusted sender
sublimemedium
Excessive AWS S3 Object Encryption with SSE-C
elastichigh
Extortion / sextortion (untrusted sender)
sublimelow
Extortion / sextortion in attachment from untrusted sender
sublimelow
Fake request for tax preparation
sublimehigh
File sharing link from suspicious sender domain
sublimemedium
Google Accelerated Mobile Pages (AMP) abuse
sublimemedium
Google Drive direct download link from unsolicited sender
sublimemedium
Headers: iOS/iPadOS mailer with invalid build number
sublimemedium
Headers: Outlook Express mailer
sublimemedium
High Process Termination Frequency
splunk_escu
HTML smuggling containing recipient email address
sublimemedium
HTML smuggling with atob in message body
sublimehigh
Image as content with a link to an open redirect
sublimehigh
Impersonation: Australian Federal Police with criminal case language
sublimehigh
Impersonation: Legal firm with copyright infringement notice
sublimemedium
Link to auto-download of a suspicious file type (unsolicited)
sublimemedium
Link to auto-downloaded disk image in encrypted zip
sublimemedium
Link to auto-downloaded DMG in archive
sublimemedium
Link to auto-downloaded DMG in encrypted zip
sublimehigh
Link to auto-downloaded file with Adobe branding
sublimehigh
Link to auto-downloaded file with Google Drive branding
sublimehigh
Link to Google Apps Script macro (unsolicited)
sublimemedium
Link to Google Apps Script macro via comment tagging
sublimemedium
Link: .onion From Unsolicited Sender
sublimelow
Link: /index.php enclosed in three asterisks
sublimemedium
Link: 9WOLF phishkit initial landing URI
sublimehigh
Link: Apple App Store malicious ad manager themed apps from free email provider
sublimemedium
Link: Commonly Abused Web Service redirecting to ZIP file
sublimemedium
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
sublimecritical
Link: Direct download of executable file
sublimelow
Link: Direct link to gamma.app document with mode parameter
sublimemedium
Link: Direct link to keap.app contact-us page
sublimemedium
Link: Direct link to limewire hosted file
sublimehigh
Link: Direct MSI download from low reputation domain
sublimelow
Link: Document-themed link to newly registered domain
sublimemedium
Link: Excessive URL rewrite encoders
sublimehigh
Link: Executable file download with suspicious message content
sublimehigh