Data Manipulation

T1565

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.

The type of modification and the impact it will have depends on the target application and process as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.

Detection rules12

Rules on DetectionCode tagged with T1565 or one of its sub-techniques.

Sigma11

Splunk1

RuleTypeRiskData sourceTechnique
Windows WBAdmin File Recovery From BackupAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1565.001

Sub-techniques3

IDNameExamples
T1565.001Stored Data Manipulation3
T1565.002Transmitted Data Manipulation5
T1565.003Runtime Data Manipulation1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupFIN13

FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money.

Software1

Used byProcedure example
MalwarePHASEJAM

PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version.

References1

  1. Sygnia Elephant Beetle Jan 2022 Open source
    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.