Defacement T1491

Tactic: Impact

Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.

Events covered

4 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 12 rules share fields, values, and exclusions.

Fields filtered most (23 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Image4ends_with 2, ne 2, eq 1*\\explorer.exe, *\\windows\\explorer.exe, \reg.exe, \svchost.exe, c:\program files (x86)\amazon\ec2launch\ec2launch.exe
Details3contains 1, eq 1, in 1(empty), *\\temp\\*, *\\users\\public\\*, 2, dword (0x00000001)
TargetObject3contains 2, ends_with 1, in 1*\\control panel\\desktop\\wallpaper, *\\control panel\\desktop\\wallpaperstyle, \control panel\desktop\wallpaper, \software\microsoft\windows\currentversion\policies\syste..., \software\microsoft\windows\currentversion\policies\syste...
Category1eq 1SQLSecurityAuditEvents
CommandLine1contains 1/d 1, /d 2, /t reg_sz
Esql.aws_cloudtrail_request_parameters_object_key1ends_with 1.js
EventID1eq 113
EventOriginalType1in 1CreateFlow, EditFlow
EventType1eq 1putobject
IsVolumeAnomalyOnVal1eq 1true
LogType1eq 1, in 1Delete, Update
OriginalFileName1eq 1reg.exe
Provider_Name1eq 1s3.amazonaws.com
ScriptBlockText1contains 1, match 1get-itemproperty, hkey_current_user\control panel\desktop\, registry::
TableName1eq 1UserInfo

Top indicator values (69 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Categoryeq
SQLSecurityAuditEvents
112
CommandLinecontains
/d 1
12
CommandLinecontains
/d 2
1
CommandLinecontains
/t reg_sz
12
CommandLinecontains
/v nochangingwallpaper
1
CommandLinecontains
/v wallpaper
1
CommandLinecontains
/v wallpaperstyle
1
CommandLinecontains
add
134
CommandLinecontains
control panel\desktop
1
CommandLinecontains
currentversion\policies\activedesktop
1
CommandLinecontains
currentversion\policies\system
1
Detailscontains
encrypted
1
Detailscontains
paying
1
Detailscontains
unlock-password
1
Detailseq
(empty)
12
Detailseq
2
14
Detailseq
dword (0x00000001)
140
Detailsin
*\\temp\\*
1
Detailsin
*\\users\\public\\*
1
Esql.aws_cloudtrail_request_parameters_object_keyends_with
.js
1
EventIDeq
13
123
EventOriginalTypein
CreateFlow
1
EventOriginalTypein
EditFlow
1
EventTypeeq
putobject
1
Imageends_with
\reg.exe
158
Imageends_with
\svchost.exe
123
Imageends_with
c:\windows\explorer.exe
1
Imageeq
c:\program files (x86)\amazon\ec2launch\ec2launch.exe
1
Imageeq
c:\program files\amazon\ec2launch\ec2launch.exe
1
Imagene
*\\explorer.exe
1

Exclusions (9 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Detailseq
(empty)
1
Imageends_with
\svchost.exe
1
Imageends_with
c:\windows\explorer.exe
1
Imageeq
c:\program files (x86)\amazon\ec2launch\ec2launch.exe
1
Imageeq
c:\program files\amazon\ec2launch\ec2launch.exe
1
TargetObjectends_with
\control panel\desktop\wallpaper
1
aws::userAgentcontains
ansible
1
aws::userAgentcontains
pulumi
1
aws::userAgentcontains
terraform
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 4 rules

Elastic 1 rule

Splunk 2 rules

Kusto 5 rules