Impact Detection Rules
The adversary is trying to manipulate, interrupt, or destroy your systems and data. Impact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries’ goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.
df00tech ships 52 production-ready detection rules mapped to the Impact tactic (TA0040). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Impact detections (52)
- CVE-2023-4346 KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout (CVE-2023-4346)
- CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Exploitation (CVE-2025-9242)
- CVE-2025-14733 CVE-2025-14733: WatchGuard Firebox Out-of-Bounds Write Exploitation
- CVE-2025-14847 MongoDB Improper Handling of Length Parameter Inconsistency (CVE-2025-14847)
- CVE-2025-54236 Adobe Commerce / Magento Improper Input Validation (CVE-2025-54236)
- CVE-2025-55182 CVE-2025-55182 — Meta React Server Components Remote Code Execution
- CVE-2025-58048 CVE-2025-58048: Paymenter Remote Code Execution via Unrestricted File Upload
- CVE-2025-61932 Motex LANSCOPE Endpoint Manager - Improper Verification of Communication Channel Source (CVE-2025-61932)
- CVE-2025-68613 n8n Improper Control of Dynamically-Managed Code Resources (CVE-2025-68613)
- CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write (CVE-2026-0300)
- CVE-2026-25108 Soliton FileZen OS Command Injection Exploitation (CVE-2026-25108)
- CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption (CVE-2026-28318)
- CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)
- CVE-2026-47396 PraisonAI Call Server Unauthenticated Agent Access (CVE-2026-47396)
- CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE via JSON Script Runner
- T1485 Data Destruction
- T1485.001 Lifecycle-Triggered Deletion
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491 Defacement
- T1491.001 Internal Defacement
- T1491.002 External Defacement
- T1495 Firmware Corruption
- T1496 Resource Hijacking
- T1496.001 Compute Hijacking
- T1496.002 Bandwidth Hijacking
- T1496.003 SMS Pumping
- T1496.004 Cloud Service Hijacking
- T1498 Network Denial of Service
- T1498.001 Direct Network Flood
- T1498.002 Reflection Amplification
- T1499 Endpoint Denial of Service
- T1499.001 OS Exhaustion Flood
- T1499.002 Service Exhaustion Flood
- T1499.003 Application Exhaustion Flood
- T1499.004 Application or System Exploitation
- T1529 System Shutdown/Reboot
- T1531 Account Access Removal
- T1561 Disk Wipe
- T1561.001 Disk Content Wipe
- T1561.002 Disk Structure Wipe
- T1565 Data Manipulation
- T1565.001 Stored Data Manipulation
- T1565.002 Transmitted Data Manipulation
- T1565.003 Runtime Data Manipulation
- T1657 Financial Theft
- T1667 Email Bombing
- THREAT-CloudBackup-SnapshotPurge Cloud Backup Vault and Snapshot Deletion Prior to Ransomware Detonation
- THREAT-EntraID-ExtortionLockout Entra ID Mass Password Reset and Account Disablement for Extortion Lockout
- THREAT-ESXi-HypervisorRansomware ESXi Hypervisor Ransomware — Mass VM Termination and Datastore Encryption
- THREAT-Ransomware-StagingIndicators Ransomware Pre-Deployment Staging Indicators
Related tactics
266 detections
225 detections