{
  "node_id": "mitre-attack-t1561-002-disk-structure-wipe",
  "title": "MITRE ATT&CK T1561.002: Disk Structure Wipe (Enterprise Tactic TA0040 - Impact)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1561.002 (Disk Structure Wipe) is an Enterprise Impact sub-technique of T1561 (Disk Wipe). Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources. Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-06, CM-02, CP-02, CP-07, CP-09, CP-10, SI-03.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1561-disk-wipe"
  ],
  "primary_citations_count": 7
}