Cipher.exe

type: OSBinaries
File Encryption Utility

Full path

c:\windows\system32\cipher.exe
c:\windows\syswow64\cipher.exe

Commands

  1. TamperUser T1485

    Can be used to forensically erase a file.

    cipher /w:{PATH_ABSOLUTE:folder}

    Zero out a file

    os: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11

  2. TamperAdmin T1562

    Can be used to impair defences by e.g. encrypting a critical EDR solution file.

    cipher.exe /e {PATH_ABSOLUTE}

    Encrypt a file

    os: Windows 10

Detection

Resources

acknowledgement: Ade Ogunsowo @i_am_tutu, Alexander Sennhauser @conitrade