M ManySignal
TA0040 ATT&CK Tactic

Impact

Impact techniques cause the primary business disruption: ransomware, data destruction, or system denial. These are the final phase of an attack — the goal is to detect and contain attackers before they reach this stage. When Impact begins, ManySignal's response automation activates immediately.

Coverage

Techniques covered
13
Pre-ransomware rules
22
Auto-containment actions
8

Threat context

How adversaries cause impact

Impact is the endgame of most financially-motivated attacks. Ransomware groups spend weeks establishing persistent access, exfiltrating data, and neutralising defenses before deploying the encryptor simultaneously across all compromised systems. The goal is to maximise the probability of payment by eliminating recovery options (backup destruction) and increasing pressure (stolen data for public release). Speed of detection in the precursor phases — not just the encryption event — determines whether an organisation recovers in hours or weeks.

ManySignal's kill-chain approach to ransomware detection prioritises the pre-encryption indicators: credential dumping, lateral movement via PsExec/WMI, and backup destruction commands. These generate Critical alerts with immediate auto-containment options well before the encrypting payload is deployed.

Impact: frequently asked questions

What is ATT&CK Impact (TA0040)?

Impact covers the techniques adversaries use to disrupt availability or compromise the integrity of data and systems. Unlike other tactics, Impact techniques are typically the final phase of an attack and represent the primary business disruption the adversary intends to cause.

How is ransomware detected before encryption begins?

ManySignal detects ransomware at the precursor stages: credential dumping (T1003), lateral movement (T1021), and backup destruction (T1490). Shadow copy deletion with vssadmin.exe is detected immediately and is a high-confidence pre-encryption indicator. When the encryption stage begins, mass file rename patterns trigger a Critical alert with immediate containment.

Can ManySignal detect crypto-mining in cloud environments?

Yes. Crypto-mining (T1496 - Resource Hijacking) leaves characteristic indicators in cloud environments: unusual EC2 instance types (GPU-accelerated), unexpected compute spend spikes, and network connections to known mining pools. ManySignal correlates these signals with the IAM identity that provisioned the resources.

Detect ransomware precursors before encryption begins

ManySignal's kill-chain detection catches credential dumping, backup destruction, and lateral spread — the signs of ransomware deployment — before data is encrypted.