MITRE ATT&CK® Ransomware Module

The MITRE ATT&CK® Ransomware Module (v1.0.2) is a subset of the MITRE ATT&CK® Module focused on techniques associated with ransomware attacks. The list of techniques included in this module comprises the techniques cited most frequently in the ransomware software entries in the MITRE ATT&CK® module.

Module Revisions

The following table summarizes the changes made for the latest release (v1.0.2) of the MITRE ATT&CK Ransomware Module.

AIE Rule ID

AIE Rule Name

Added


1559

1562.002: Impair Defenses: Disable Windows Event Logging