{
  "technique_id": "T1486",
  "mappings": [
    {
      "attack_technique": "T1486 Data Encrypted for Impact",
      "d3fend_technique": "File Integrity Monitoring",
      "soc_action": "Detect mass file rename/modification patterns and ransom note file creation across shares and endpoints.\n",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1486 Data Encrypted for Impact",
      "d3fend_technique": "File Analysis",
      "soc_action": "Analyze the encrypting binary and ransom note for known ransomware family indicators.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1486 Data Encrypted for Impact",
      "d3fend_technique": "File Eviction",
      "soc_action": "Remove the encryptor binary and any dropped ransom-note artifacts once isolated.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1486 Data Encrypted for Impact",
      "d3fend_technique": "Restore File",
      "soc_action": "Restore encrypted data from an offline/immutable backup once a clean restore point predating compromise is confirmed.\n",
      "tooling": [
        "Backup platform"
      ]
    }
  ]
}