Compliance Node Overview
MITRE ATT&CK T1561.001 (Disk Content Wipe) is an Enterprise Impact sub-technique of T1561 (Disk Wipe). Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources. Adversaries may partially or completely overwrite the contents of a storage device rendering the data irrecoverable through the storage interface. Instead of wiping specific disk structures or files, adversaries with destructive intent may wipe arbitrary portions of disk content. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1053 Data Backup. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-06, CM-02, CP-02, CP-07, CP-09, CP-10, SI-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1561/001/
SHA-256 integrity: bd349d8668da9c485db9769ba5ca33d07e17d144f7e6e0bb1fefa93bea0d9829
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1561.001: Disk Content Wipe (https://attack.mitre.org/techniques/T1561/001/)
- MITRE ATT&CK Tactic TA0040: Impact (https://attack.mitre.org/tactics/TA0040/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access