Defacement

T1491

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.

Detection rules6

Rules on DetectionCode tagged with T1491 or one of its sub-techniques.

Sigma4

Splunk2

RuleTypeRiskData sourceTechnique
Modification Of WallpaperTTPNULLSysmon EventID 13T1491
Windows Defacement Modify Transcodedwallpaper FileAnomalyNULLSysmon EventID 1 AND Sysmon EventID 11T1491

Sub-techniques2

IDNameExamples
T1491.001Internal Defacement15
T1491.002External Defacement2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.