Data Manipulation T1565

Tactic: Impact

Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 72 rules share fields, values, and exclusions.

Fields filtered most (99 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType16eq 10, in 4, contains 1, ne 1exec, PutObject, baseline deviation, createdatasource, deletedatasource
data_stream.dataset14eq 14aws.cloudtrail, github.audit, gcp.audit, kubernetes.audit_logs, network_traffic.memcached
DataSource11eq 11CHANGEDOC_BANK, CHANGEDOC_BUPA_BANK, CHANGEDOC_CCARD, CHANGEDOC_DEBI, CHANGEDOC_GENERIC
Provider_Name8eq 8s3.amazonaws.com, bedrock.amazonaws.com, cloudtrail.amazonaws.com, ec2.amazonaws.com, microsoft-windows-iphlpsvc
event.outcome8eq 8success
DeviceEventClassID5contains 4, eq 1RPZ, DNS Response
count_5gt 5200, 1
CommandLine4contains 4, ends_with 2, match 1, starts_with 1--cipher, .history, /.bash_history, /.zsh_history, /bin/login
Image4ends_with 3, is_not_null 1/bin/sed, /cat, /diskutil, /echo, /gpg
Active3eq 3true
DAVISRiskLevel3eq 2, ne 1CRITICAL
Description3contains 2, eq 1Infoblox, Infoblox - HOST - Policy, Infoblox - URL, MalwareC2
DomainName3is_not_null 3
HitTime3cross_field_compare 3ExpirationDateTime, TimeGenerated
Muted3eq 3false

Top indicator values (261 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
8369
data_stream.dataseteq
aws.cloudtrail
6169
data_stream.dataseteq
github.audit
418
DeviceEventClassIDcontains
RPZ
44
Activeeq
true
370
HitTimecross_field_compare
ExpirationDateTime
33
HitTimecross_field_compare
TimeGenerated
33
Mutedeq
false
33
Provider_Nameeq
s3.amazonaws.com
315
ThreatLevel_Scorege
80
33
count_gt
200
35
count_gt
1
28
ComplianceStatuseq
FAILED
28
DAVISRiskLeveleq
CRITICAL
22
EventTypeeq
exec
2576
LogTypeeq
Update
23
RecordStateeq
ACTIVE
28
aws::eventSourceeq
ec2.amazonaws.com
219
event.categoryeq
file
243
event.typeeq
change
294
github.categoryeq
protected_branch
24
kubernetes.audit.verbin
delete
26
kubernetes.audit.verbin
patch
220
kubernetes.audit.verbin
update
219
AwsSecurityFindingGeneratorIdeq
security-control/CloudTrail.2
1
AwsSecurityFindingGeneratorIdeq
security-control/SQS.1
1
Categoryeq
SQLSecurityAuditEvents
112
CommandLinecontains
--cipher
1
CommandLinecontains
/.bash_history
12
CommandLinecontains
/.zsh_history
12

Exclusions (36 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineends_with
/etc/mdadm/mdadm.conf
1
CommandLinestarts_with
sed -i /^*
1
CommandLinestarts_with
sed -ne s/^
1
Imageends_with
/bin/sed
1
Imageeq
/usr/bin/pacman
1
Imageeq
/usr/lib/dracut/dracut-install
1
Imagestarts_with
/opt/sophos-spl/plugins/av/bin/
1
Imagestarts_with
/var/lib/elastic-agent/
1
IsatapRoutereq
127.0.0.1
1
IsatapRoutereq
::1
1
aws.cloudtrail.resources.arnregex_match
.*(AWSLogs|CloudTrail|access-logs).*
1
aws::userAgentcontains
ansible
1
aws::userAgentcontains
pulumi
1
aws::userAgentcontains
terraform
1
aws::userIdentity.typeeq
AWSService
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 13 rules

Elastic 19 rules

Splunk 1 rule

Kusto 37 rules

Panther 2 rules