Impact
Impact techniques cause the primary business disruption: ransomware, data destruction, or system denial. These are the final phase of an attack — the goal is to detect and contain attackers before they reach this stage. When Impact begins, ManySignal's response automation activates immediately.
Coverage
- Techniques covered
- 13
- Pre-ransomware rules
- 22
- Auto-containment actions
- 8
Threat context
How adversaries cause impact
Impact is the endgame of most financially-motivated attacks. Ransomware groups spend weeks establishing persistent access, exfiltrating data, and neutralising defenses before deploying the encryptor simultaneously across all compromised systems. The goal is to maximise the probability of payment by eliminating recovery options (backup destruction) and increasing pressure (stolen data for public release). Speed of detection in the precursor phases — not just the encryption event — determines whether an organisation recovers in hours or weeks.
ManySignal's kill-chain approach to ransomware detection prioritises the pre-encryption indicators: credential dumping, lateral movement via PsExec/WMI, and backup destruction commands. These generate Critical alerts with immediate auto-containment options well before the encrypting payload is deployed.
Impact techniques ManySignal detects
Data Encrypted for Impact
Ransomware encryption of files, databases, or cloud storage for extortion.
Data Destruction
Wiping disks, deleting cloud resources, or overwriting data without encryption.
Inhibit System Recovery
Deleting shadow copies, disabling backup services, and removing recovery catalogs.
Endpoint Denial of Service
Resource exhaustion attacks targeting application or network endpoints.
Resource Hijacking
Crypto-mining, compute abuse, and API quota exhaustion using compromised cloud credentials.
Impact: frequently asked questions
What is ATT&CK Impact (TA0040)?
Impact covers the techniques adversaries use to disrupt availability or compromise the integrity of data and systems. Unlike other tactics, Impact techniques are typically the final phase of an attack and represent the primary business disruption the adversary intends to cause.
How is ransomware detected before encryption begins?
ManySignal detects ransomware at the precursor stages: credential dumping (T1003), lateral movement (T1021), and backup destruction (T1490). Shadow copy deletion with vssadmin.exe is detected immediately and is a high-confidence pre-encryption indicator. When the encryption stage begins, mass file rename patterns trigger a Critical alert with immediate containment.
Can ManySignal detect crypto-mining in cloud environments?
Yes. Crypto-mining (T1496 - Resource Hijacking) leaves characteristic indicators in cloud environments: unusual EC2 instance types (GPU-accelerated), unexpected compute spend spikes, and network connections to known mining pools. ManySignal correlates these signals with the IAM identity that provisioned the resources.
Detect ransomware precursors before encryption begins
ManySignal's kill-chain detection catches credential dumping, backup destruction, and lateral spread — the signs of ransomware deployment — before data is encrypted.