Skip to content

S1205 cipher.exe

cipher.exe is a native Microsoft utility that manages encryption of directories and files on NTFS (New Technology File System) partitions by using the Encrypting File System (EFS).1

Item Value
ID S1205
Associated Names
Type TOOL
Version 1.0
Created 25 February 2025
Last Modified 10 March 2025
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1561 Disk Wipe -
enterprise T1561.001 Disk Content Wipe cipher.exe can be used to overwrite deleted data in specified folders.2

Groups That Use This Software

ID Name References
G0007 APT28 2

References