This detection identifies adversaries utilizing destructive hard drive tools to intentionally erase or corrupt storage media, a tactic often employed during data exfiltration cover-ups or post-compromise cleanup phases. Proactively hunting for this behavior in Azure Sentinel is critical because low-severity alerts may indicate early-stage infrastructure sabotage that could escalate into significant operational downtime if not correlated with other suspicious activities before full system failure occurs.
rule DestructiveHardDriveTool1
{
strings:
$str0= "MZ"
$str1 = {c6 84 24 ?? ( 00 | 01 ) 00 00 }
$xorInLoop = { 83 EC 20 B9 08 00 00 00 33 D2 56 8B 74 24 30 57 8D 7C 24 08 F3 A5 8B 7C 24 30 85 FF 7E 3A 8B 74 24 2C 8A 44 24 08 53 8A 4C 24 21 8A 5C 24 2B 32 C1 8A 0C 32 32 C3 32 C8 88 0C 32 B9 1E 00 00 00 8A 5C 0C 0C 88 5C 0C 0D 49 83 F9 FF 7F F2 42 88 44 24 0C 3B D7 7C D0 5B 5F 5E 83 C4 20 C3 }
condition:
$str0 at 0 and $xorInLoop and #str1 > 300
}
This YARA rule can be deployed in the following contexts:
This rule contains 3 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the DestructiveHardDriveTool1 detection rule, tailored for an enterprise environment:
Scheduled Data Sanitization by IT Operations
DBAN (Darik's Boot and Nuke) or Parted Magic utilities, which trigger the rule due to their aggressive overwrite patterns.dban.exe) running from a known management server IP range during the maintenance window (e.g., Sundays 02:00–04:00 UTC).Endpoint Protection Agent Self-Healing
MsMpEng.exe (Defender) or csfalcon.exe (CrowdStrike) when they invoke child processes related to disk management, specifically filtering out events where the command line contains flags like /repair or /clean.Software Deployment via Configuration Management
diskpart utility is frequently called within these scripts to partition and format local SSDs before installing new images.