Data Manipulation T1565
Tactic: Impact
Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.
Events covered
7 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 11 | FileCreate |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| ESF | exec | Process Execution |
| Iphlpsvc | Event ID 4100 | ISATAP router address IsatapRouter was set with status ErrorCode. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 72 rules share fields, values, and exclusions.
Fields filtered most (99 distinct)
These fields appear most often in rule filters.
Top indicator values (261 distinct)
These values appear most often in rule predicates.
Exclusions (36 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 13 rules
- AWS EC2 Disable EBS Encryption
- Azure Device or Configuration Modified or Deleted
- Azure DNS Zone Modified or Deleted
- Cisco Denial of Service
- Cisco Modify Configuration
- Commands to Clear or Remove the Syslog - Builtin
- DNS hosts file modified
- Google Cloud Re-identifies Sensitive Information
- History File Deletion
- ISATAP Router Address Was Set
- macOS Encryption Tool Usage
- Potential Suspicious Change To Sensitive/Critical Files
- Powershell Add Name Resolution Policy Table Rule
Elastic 19 rules
- Agent Spoofing - Multiple Hosts Using Same Agent
- AWS Bedrock Knowledge Base or RAG Data Source Tampering
- AWS CloudTrail Log Updated
- AWS EC2 Encryption Disabled
- AWS S3 Static Site JavaScript File Uploaded
- AWS S3 Unauthenticated Bucket Access by Rare Source
- Deprecated - M365 Security Compliance Potential Ransomware Activity
- First Time Seen Memcached Writer
- GitHub Actions Unusual Bot Push to Repository
- GKE CoreDNS or Kube-DNS Configuration Modified
- High Number of Closed Pull Requests by User
- High Number of Protected Branch Force Pushes by User
- Hosts File Modified
- Kubernetes CoreDNS or Kube-DNS Configuration Modified
- Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
- Potential AWS S3 Bucket Ransomware Note Uploaded
- Several Failed Protected Branch Force Pushes by User
- Suspicious Recursive File Deletion via Built-In Utilities
- Suspicious Sysctl File Event
Splunk 1 rule
Kusto 37 rules
- Affected rows stateful anomaly on database
- AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
- AWS Security Hub - Detect SQS Queue lacking encryption at rest
- Claroty - Critical baseline deviation
- Copilot - Jailbreak Attempt Detected
- Dataverse - Mass record updates
- Dynatrace - Problem detection
- Dynatrace Application Security - Attack detection
- Dynatrace Application Security - Code-Level runtime vulnerability detection
- Dynatrace Application Security - Non-critical runtime vulnerability detection
- Dynatrace Application Security - Third-Party runtime vulnerability detection
- F&O - Mass update or deletion of user records
- F&O - Reverted bank account number modifications
- Infoblox - Data Exfiltration Attack
- Infoblox - High Threat Level Query Not Blocked Detected
- Infoblox - IQ for TD Detected Insights - API Source
- Infoblox - IQ for TD Insight Detected - CDC Source
- Infoblox - Many High Threat Level Queries From Single Host Detected
- Infoblox - Many High Threat Level Single Query Detected
- Infoblox - Many NXDOMAIN DNS Responses Detected
- Infoblox - SOC Insight Detected - API Source
- Infoblox - SOC Insight Detected - CDC Source
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains
- Infoblox - TI - Syslog Match Found - URL
- Pathlock TDnR - Bank Master Data Changes
- Pathlock TDnR - Business Partner Bank Data Changes
- Pathlock TDnR - Credit Card Data Changes
- Pathlock TDnR - Debitor Change Documents
- Pathlock TDnR - G/L Account Changes
- Pathlock TDnR - Generic SAP Change Documents
- Pathlock TDnR - Generic Table Content Changes
- Pathlock TDnR - HR User Master Change Requests
- Pathlock TDnR - IBAN Change Documents
- Pathlock TDnR - Payment Request Changes
- Pathlock TDnR - Vendor Change Documents
- Votiro - File Blocked from Connector