cipher.exe

cipher.exe is a native Microsoft utility that manages encryption of directories and files on NTFS (New Technology File System) partitions by using the Encrypting File System (EFS).[1]

ID: S1205
Type: TOOL
Platforms: Windows
Version: 1.0
Created: 25 February 2025
Last Modified: 10 March 2025

Techniques Used

Domain ID Name Use
Enterprise T1561 .001 Disk Wipe: Disk Content Wipe

cipher.exe can be used to overwrite deleted data in specified folders.[2]

Groups That Use This Software

ID Name References
G0007 APT28

[2]

Campaigns

References