Impact Detection Rules
The adversary is trying to manipulate, interrupt, or destroy your systems and data. Impact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries’ goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.
df00tech ships 74 production-ready detection rules mapped to the Impact tactic (TA0040). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Impact detections (74)
- CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Exploitation Attempt (CVE-2021-27137)
- CVE-2023-4346 KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout (CVE-2023-4346)
- CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Exploitation (CVE-2025-9242)
- CVE-2025-14733 CVE-2025-14733: WatchGuard Firebox Out-of-Bounds Write Exploitation
- CVE-2025-14847 MongoDB Improper Handling of Length Parameter Inconsistency (CVE-2025-14847)
- CVE-2025-54236 Adobe Commerce / Magento Improper Input Validation (CVE-2025-54236)
- CVE-2025-55182 CVE-2025-55182 — Meta React Server Components Remote Code Execution
- CVE-2025-58048 CVE-2025-58048: Paymenter Remote Code Execution via Unrestricted File Upload
- CVE-2025-61932 Motex LANSCOPE Endpoint Manager - Improper Verification of Communication Channel Source (CVE-2025-61932)
- CVE-2025-68613 n8n Improper Control of Dynamically-Managed Code Resources (CVE-2025-68613)
- CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write (CVE-2026-0300)
- CVE-2026-20349 Cisco ASA/FTD VPN Web Services Heap Inspection DoS (CVE-2026-20349)
- CVE-2026-25108 Soliton FileZen OS Command Injection Exploitation (CVE-2026-25108)
- CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption (CVE-2026-28318)
- CVE-2026-33824 CVE-2026-33824 — Microsoft IKE Service Extensions Double Free Exploitation
- CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)
- CVE-2026-47396 PraisonAI Call Server Unauthenticated Agent Access (CVE-2026-47396)
- CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE via JSON Script Runner
- CVE-2026-48204 Apache Camel camel-mongodb-gridfs Header Injection / GridFS Operation Override (CVE-2026-48204)
- CVE-2026-50027 MCP Memory Service Unauthenticated Document API Access (CVE-2026-50027)
- CVE-2026-52778 YesWiki Formula Calculator Unsafe eval() Remote Code Execution (CVE-2026-52778)
- CVE-2026-54658 CVE-2026-54658 - @hypequery/clickhouse SQL Injection via Parameter Escaping
- CVE-2026-55209 resdata < 6.2.9 Memory-Corruption Vulnerabilities (CVE-2026-55209)
- CVE-2026-55211 CVE-2026-55211: surfio Out-of-Bounds Read (CWE-125)
- T1485 Data Destruction
- T1485.001 Lifecycle-Triggered Deletion
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491 Defacement
- T1491.001 Internal Defacement
- T1491.002 External Defacement
- T1495 Firmware Corruption
- T1496 Resource Hijacking
- T1496.001 Compute Hijacking
- T1496.002 Bandwidth Hijacking
- T1496.003 SMS Pumping
- T1496.004 Cloud Service Hijacking
- T1498 Network Denial of Service
- T1498.001 Direct Network Flood
- T1498.002 Reflection Amplification
- T1499 Endpoint Denial of Service
- T1499.001 OS Exhaustion Flood
- T1499.002 Service Exhaustion Flood
- T1499.003 Application Exhaustion Flood
- T1499.004 Application or System Exploitation
- T1529 System Shutdown/Reboot
- T1531 Account Access Removal
- T1561 Disk Wipe
- T1561.001 Disk Content Wipe
- T1561.002 Disk Structure Wipe
- T1565 Data Manipulation
- T1565.001 Stored Data Manipulation
- T1565.002 Transmitted Data Manipulation
- T1565.003 Runtime Data Manipulation
- T1657 Financial Theft
- T1667 Email Bombing
- THREAT-BEC-InvoiceRedirectWireFraud BEC Invoice Redirect - Hidden Inbox Rule Paired With Fraudulent Wire Transfer Instructions to Accounts Payable
- THREAT-CloudAI-AzureOpenAIKeyHijacking Azure OpenAI API Key Theft and Reverse-Proxy Resale (LLMjacking)
- THREAT-CloudBackup-SnapshotPurge Cloud Backup Vault and Snapshot Deletion Prior to Ransomware Detonation
- THREAT-EntraID-ExtortionLockout Entra ID Mass Password Reset and Account Disablement for Extortion Lockout
- THREAT-ESXi-HypervisorRansomware ESXi Hypervisor Ransomware — Mass VM Termination and Datastore Encryption
- THREAT-Impact-BECFinancialTheftWireTransfer BEC Financial Theft — Fraudulent Wire/ACH Transfer Initiation via Mailbox Tampering and Invoice Fraud
- THREAT-Impact-CloudGPUCryptojackingBurstProvisioning Cloud GPU / Compute-Optimized Instance Burst Provisioning for Cryptocurrency Mining
- THREAT-Impact-DiskWipeUtilityExecution Disk Wipe — Destructive Disk-Clearing Utility Execution
- THREAT-Impact-EndpointResourceExhaustionDoS Endpoint Denial of Service via Process/Service Resource Exhaustion Flood
- THREAT-Impact-FinancialLedgerTampering Financial Ledger and Transaction Record Tampering via Direct Database Manipulation
- THREAT-Impact-ProductionDatabaseRecordTampering Stored Data Manipulation — Unauthorized Bulk Modification of Production Database Records
- THREAT-Impact-PublicWebsiteDefacement Public Website Defacement via Compromised CMS Admin Session or Mass Static Asset Tampering
- THREAT-Impact-SecurityAgentServiceTermination Security Agent Service Termination — EDR/AV/Backup-Agent Kill Chain Prelude to Destructive Payload
- THREAT-Impact-SecurityToolMassServiceStop Mass Stop/Disable of AV, EDR, and Backup Agent Services Preceding Destructive Activity
- THREAT-Impact-VSSShadowCopyDeletion Shadow Copy and Backup Catalog Deletion via vssadmin/wbadmin/wmic
- THREAT-K8s-CryptojackingResourceHijack Kubernetes Cryptojacking — Cloud Compute Hijacking via Malicious Pod Deployment
- THREAT-Ransomware-StagingIndicators Ransomware Pre-Deployment Staging Indicators
Related tactics
292 detections
276 detections