Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Intermittent Encryption
Threats, Abuse & Incident Response

Intermittent Encryption

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Threats, Abuse & Incident Response

Intermittent encryption is a ransomware technique that encrypts only part of each file rather than the entire file at once. This reduces processing time and can make malicious activity harder to spot. Defenders should treat it as a stealthier encryption pattern that still produces operational disruption and extortion risk.

What Intermittent Encryption Means in Ransomware

Intermittent encryption is a ransomware optimization, not a separate attack family. By encrypting only selected portions of each file, the malware can preserve the same extortion outcome while reducing CPU time, shortening dwell time, and limiting the chance that bulk file activity is noticed quickly.

How Partial-File Encryption Changes Detection

The security significance of intermittent encryption is the mismatch between visible activity and business impact. File contents are still being altered, but the pattern may look less like a classic full-file scramble and more like a bursty write workload, which can delay detection in endpoint, backup, and file-integrity monitoring.

That pattern also changes what defenders need to watch. Alerts that depend on long sustained encryption runs, obvious extension changes, or large-volume file rewrites can underperform when the attacker spreads damage across many files in smaller slices.

Why It Preserves Ransomware Leverage

Intermittent encryption keeps the coercive part of ransomware intact: key business files become unreadable enough to interrupt operations, recovery pressure rises, and victims still face a pay-or-rebuild decision. The technique mainly improves attacker efficiency, which can let encryption complete before a response team intervenes.

Because the method lowers the attacker’s processing cost, it can also support faster execution across more hosts. That makes the technique attractive in hands-on intrusions where the operator wants maximum disruption from a limited window of access.

Defensive Controls and Response Focus

Defenders should treat intermittent encryption as a pattern that requires layered detection, resilient backups, and fast containment. Controls that understand file modification behavior, suspicious process ancestry, and unusual access to high-value shares are more useful than controls that only look for a single mass-encryption signature.

Recovery planning matters because partial encryption still destroys usability. Immutable or offline backups, tested restore procedures, and segmentation of critical data stores reduce the chance that a stealthier encryption pattern turns into a broad outage. NIST SP 800-53 Rev 5 Security and Privacy Controls is a useful reference point for mapping those protective and recovery controls to monitoring, access control, and system integrity expectations.

Risk and Threat Considerations

Intermittent encryption raises risk because it can delay detection while still creating severe operational disruption. The attacker benefits from a quieter execution profile, and the victim may discover the damage only after key business data is already partially unusable.

Failure mechanism: Partial-file modification reduces the volume and duration of obvious encryption activity, which can let ransomware evade pattern-based detection and finish before containment.

Impact: Organizations can lose availability, integrity, and recovery confidence even when the encryption does not look “complete” in the classic sense, increasing extortion pressure and downtime.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1486 — Data Encrypted for ImpactIntermittent encryption is a ransomware variant of data encryption for impact.
Recommendation — Map partial-encryption behavior to T1486 and tune detections for bursty file modification patterns.
NIST CSF 2.0DE.CM-09 — Monitoring for Anomalies and EventsStealthier encryption patterns require anomaly monitoring to detect unusual file activity.
RC.RP-01 — Recovery Plan ExecutedRansomware disruption makes recovery execution central to this technique's impact.
Recommendation — Correlate file-write spikes and process behavior under DE.CM-09 to catch intermittent encryption earlier. Validate recovery plan execution with clean restore tests so partial encryption does not prolong outage.
NIST SP 800-53 Rev 5SI-4 — System MonitoringPartial encryption is best detected through continuous system and file activity monitoring.
CP-9 — System BackupResilient backups are the key control against ransomware file corruption and extortion.
Recommendation — Deploy SI-4 telemetry for suspicious file modification bursts and abnormal process ancestry. Use CP-9 to maintain recoverable backups that remain usable after partial-file encryption.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org