Detect Disk Wipe — Destructive Disk-Clearing Utility Execution in Google Chronicle
Wiper attacks and the destructive final stage of some ransomware/extortion intrusions rely on a small, well-known set of disk-clearing tools and commands rather than custom code, because overwriting or reformatting a disk does not require sophistication — it requires only that the operator have sufficient privilege and be willing to accept the outcome. Common patterns: Sysinternals sdelete/sdelete64 invoked with the -p (passes), -z (zero free space), or -c (clean free space) flags to securely overwrite file or free-space content; cipher.exe /w: to wipe deallocated disk space (a native Windows binary requiring no download, favored specifically because it evades application-allowlisting that would block sdelete); diskpart.exe run non-interactively via a script file containing "clean" or "clean all" against a selected disk/volume; format.com or PowerShell's Clear-Disk/Remove-Partition/Initialize-Disk cmdlets invoked with -Confirm:$false against a data or boot volume; and on Linux, dd with if=/dev/zero or if=/dev/urandom targeting a block device, shred -vfz, or wipefs -a. WhisperGate and Shamoon-family wipers used variations of these same primitives (WhisperGate additionally corrupted the MBR directly). None of these tools/commands has a legitimate high-volume production use case against a system or data volume — they appear almost exclusively during authorized secure-decommissioning workflows or a destructive attack, making this a high-fidelity, low-noise detection surface when properly scoped away from asset-disposal processes.
MITRE ATT&CK
- Tactic
- Impact
YARA-L Detection Query
rule disk_wipe_utility_execution {
meta:
author = "df00tech Detection Engineering"
description = "Detects execution of common disk/data-wipe utilities and commands (sdelete, cipher /w:, diskpart clean, format, dd/shred/wipefs)"
severity = "CRITICAL"
priority = "HIGH"
mitre_attack_tactic = "Impact"
mitre_attack_technique = "T1561.001"
created = "2026-07-18"
events:
$proc.metadata.event_type = "PROCESS_LAUNCH"
(
(re.regex($proc.target.process.file.full_path, `(?i)sdelete(64)?[.]exe`) and re.regex($proc.target.process.command_line, `(?i)(-p|-z|-c)\b`)) or
(re.regex($proc.target.process.file.full_path, `(?i)cipher[.]exe`) and re.regex($proc.target.process.command_line, `(?i)/w:`)) or
(re.regex($proc.target.process.file.full_path, `(?i)diskpart[.]exe`) and re.regex($proc.target.process.command_line, `(?i)/s\b`)) or
(re.regex($proc.target.process.file.full_path, `(?i)format[.]com`) and re.regex($proc.target.process.command_line, `(?i)(/y|/fs)`)) or
(re.regex($proc.target.process.file.full_path, `(?i)(^|\/)dd(\.exe)?$`) and re.regex($proc.target.process.command_line, `(?i)of=\/dev\/(sd|nvme|vd)`)) or
(re.regex($proc.target.process.file.full_path, `(?i)(^|\/)shred$`) and re.regex($proc.target.process.command_line, `(?i)-(v)?fz`)) or
(re.regex($proc.target.process.file.full_path, `(?i)(^|\/)wipefs$`) and re.regex($proc.target.process.command_line, `(?i)-a\b`))
)
condition:
$proc
} Chronicle YARA-L 2.0 rule matching UDM PROCESS_LAUNCH events for the full disk-wipe primitive set across Windows and Linux.
Data Sources
Required Tables
False Positives & Tuning
- Documented decommissioning workflows
- Forensic imaging processes
Other platforms for THREAT-Impact-DiskWipeUtilityExecution
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Simulate sdelete Secure Overwrite
Expected signal: Sysmon Event ID 1: sdelete64.exe process creation with '-p' flag in command line.
- Test 2Simulate Diskpart Scripted Clean
Expected signal: Sysmon Event ID 1: diskpart.exe process creation with '/s' flag referencing the script file.
- Test 3Simulate dd Block Device Overwrite (Linux)
Expected signal: auditd EXECVE record for dd with of=/dev/loop9 and if=/dev/zero in the argument list.
Response Playbook
Triage
- Treat any diskpart clean/clean all, format, or dd-to-raw-device execution against a production host as a potential active-destruction event requiring immediate response — do not wait for confirmation if the target is not a documented decommission asset.
- Check whether the host/device is on the approved asset-decommissioning list or in a known reimaging/staging workflow; if not, escalate immediately.
- Identify the account and process ancestry: was this launched interactively, via a remote execution tool (PsExec/WinRM/SSH), or via a scheduled task — the latter two suggest a broader compromise enabling remote destructive action.
- Determine scope: is this a single host, or are multiple hosts showing wipe-tool execution in the same short window (indicates a coordinated wiper deployment, as seen with WhisperGate and Shamoon)?
- Check for accompanying indicators of a broader destructive campaign: MBR/bootloader modification, backup deletion (T1490), or credential-dumping activity preceding the wipe command.
Containment
- Immediately power off or isolate the affected host if the wipe command has not yet completed — physical power removal may be necessary if network isolation cannot stop an in-progress low-level disk write.
- If multiple hosts show the same indicator, isolate the entire affected segment from the network immediately to prevent further propagation of the wipe trigger (e.g., a malicious GPO or remote script).
- Disable the account and any remote-execution session used to launch the wipe command across the environment.
- Verify backup integrity and isolate backup infrastructure from the network if a coordinated wiper event is suspected — attackers frequently target backups first or simultaneously.
- Do not attempt data recovery on the affected disk until forensic imaging (if any partition remains readable) has been completed.
Evidence Collection
- Full command line and parent process chain for the wipe-tool execution
- Account and authentication context: interactive logon, RDP, PsExec, WinRM, or SSH session details
- Any scheduled task, GPO, or remote script repository (SMB share, config management tool) that could have distributed the wipe command to multiple hosts
- Preceding process history on the host for the prior 24-48 hours (credential dumping, lateral movement, backup deletion)
- Disk imaging of any partially-wiped or unaffected sibling disks for forensic analysis, if feasible before further overwrite occurs
Escalation Criteria
- !Wipe-tool execution detected against a host not on the documented decommission/reimaging list — immediate incident declaration
- !Diskpart clean/clean all, format, or dd-to-device detected on a production server, domain controller, or hypervisor host
- !Multiple hosts show wipe indicators within the same short window
- !Wipe activity follows or accompanies backup/shadow-copy deletion (T1490) or credential-dumping activity — indicates a full destructive campaign rather than isolated misuse
Investigation Guide
Related Techniques
Forensic Artifacts
- >
Sysmon Event ID 1 (Process Create) for sdelete, cipher, diskpart, format.com, PowerShell disk cmdlets - >
Diskpart script files (referenced via /s) left on disk or in temp directories before execution - >
Linux auditd EXECVE records for dd, shred, wipefs with full argument list - >
Windows Event ID 1006 (chkdsk) or disk subsystem errors that may follow a partial or interrupted wipe attempt - >
PowerShell script block logging (Event ID 4104) capturing the full Clear-Disk/Remove-Partition/Initialize-Disk invocation
Tuning Guidance
Maintain an allowlist of accounts/service accounts and hostnames associated with the organization's legitimate asset-decommissioning and reimaging workflows, and exclude those specific account+host combinations rather than the tool name broadly — the tools themselves have essentially no other legitimate production use, so tool-name-level exclusion defeats the purpose of the detection. Where possible, require decommissioning workflows to run from a small, fixed set of jump hosts so exclusions stay narrow and auditable.
Hunting Queries
30-day hunt establishing a baseline of legitimate disk-wipe-tool usage by account and device, to distinguish routine decommissioning activity from anomalous or first-time usage by an account with no prior history of running these tools.
DeviceProcessEvents
| where Timestamp > ago(30d)
| where FileName in~ ("sdelete.exe", "sdelete64.exe", "diskpart.exe", "cipher.exe")
| summarize Count=count(), Devices=make_set(DeviceName) by FileName, AccountName
| sort by Count desc index=mde sourcetype="DeviceProcessEvents" earliest=-30d FileName IN ("sdelete.exe","sdelete64.exe","diskpart.exe","cipher.exe")
| stats count AS Count, values(DeviceName) AS Devices by FileName, AccountName
| sort - Count Atomic Red Team Tests
Runs Sysinternals sdelete against a disposable test file with the secure-overwrite flag, simulating anti-forensic file wiping. Requires sdelete to be present; run only in a lab environment against test data.
Command
sdelete64.exe -p 3 C:\Temp\test-wipe-target.txt Expected Telemetry
Sysmon Event ID 1: sdelete64.exe process creation with '-p' flag in command line.
Expected Detection
Alert fires on SdeleteSecureOverwrite indicator with RiskScore=85.
Invokes diskpart non-interactively with a script file containing a 'clean' command against a test/scratch virtual disk. Run only in an isolated lab VM against a disposable virtual disk — never against a production or shared disk.
Command
echo select disk 9 > C:\Temp\wipe.txt & echo clean >> C:\Temp\wipe.txt & diskpart /s C:\Temp\wipe.txt Cleanup
del C:\Temp\wipe.txt Expected Telemetry
Sysmon Event ID 1: diskpart.exe process creation with '/s' flag referencing the script file.
Expected Detection
Alert fires on DiskpartScriptedClean indicator with RiskScore=100 — highest-severity destructive-operation tier.
Writes zeros to a disposable loopback device using dd, simulating the Linux disk-wipe primitive. Run only against a loopback/scratch device created specifically for this test — never against a real block device.
Command
dd if=/dev/zero of=/dev/loop9 bs=1M count=10 Expected Telemetry
auditd EXECVE record for dd with of=/dev/loop9 and if=/dev/zero in the argument list.
Expected Detection
Alert fires on DdBlockDeviceOverwrite indicator with RiskScore=100.