Cipher.exe

File Encryption Utility

Paths

  • c:\windows\system32\cipher.exe
  • c:\windows\syswow64\cipher.exe

Commands

Tamper

Zero out a file

Use case: Can be used to forensically erase a file.

Privileges: User

cipher /w:{PATH_ABSOLUTE:folder}

Tamper

Encrypt a file

Use case: Can be used to impair defences by e.g. encrypting a critical EDR solution file.

Privileges: Admin

cipher.exe /e {PATH_ABSOLUTE}

Detection

Resources