Data Manipulation T1565
Tactic: Impact
Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.
Events covered
5 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Iphlpsvc | Event ID 4100 | ISATAP router address IsatapRouter was set with status ErrorCode. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
Patterns shared across the 69 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (87 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (235 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (31 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 13 rules
- AWS EC2 Disable EBS Encryption
- Azure Device or Configuration Modified or Deleted
- Azure DNS Zone Modified or Deleted
- Cisco Denial of Service
- Cisco Modify Configuration
- Commands to Clear or Remove the Syslog - Builtin
- DNS hosts file modified
- Google Cloud Re-identifies Sensitive Information
- History File Deletion
- ISATAP Router Address Was Set
- macOS Encryption Tool Usage
- Potential Suspicious Change To Sensitive/Critical Files
- Powershell Add Name Resolution Policy Table Rule
Elastic 16 rules
- Agent Spoofing - Multiple Hosts Using Same Agent
- AWS Bedrock Knowledge Base or RAG Data Source Tampering
- AWS CloudTrail Log Updated
- AWS EC2 Encryption Disabled
- AWS S3 Static Site JavaScript File Uploaded
- AWS S3 Unauthenticated Bucket Access by Rare Source
- Deprecated - M365 Security Compliance Potential Ransomware Activity
- GitHub Actions Unusual Bot Push to Repository
- High Number of Closed Pull Requests by User
- High Number of Protected Branch Force Pushes by User
- Hosts File Modified
- Kubernetes CoreDNS or Kube-DNS Configuration Modified
- Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
- Potential AWS S3 Bucket Ransomware Note Uploaded
- Several Failed Protected Branch Force Pushes by User
- Suspicious Sysctl File Event
Splunk 1 rule
Kusto 37 rules
- Affected rows stateful anomaly on database
- AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
- AWS Security Hub - Detect SQS Queue lacking encryption at rest
- Claroty - Critical baseline deviation
- Copilot - Jailbreak Attempt Detected
- Dataverse - Mass record updates
- Dynatrace - Problem detection
- Dynatrace Application Security - Attack detection
- Dynatrace Application Security - Code-Level runtime vulnerability detection
- Dynatrace Application Security - Non-critical runtime vulnerability detection
- Dynatrace Application Security - Third-Party runtime vulnerability detection
- F&O - Mass update or deletion of user records
- F&O - Reverted bank account number modifications
- Infoblox - Data Exfiltration Attack
- Infoblox - High Threat Level Query Not Blocked Detected
- Infoblox - Many High Threat Level Queries From Single Host Detected
- Infoblox - Many High Threat Level Single Query Detected
- Infoblox - Many NXDOMAIN DNS Responses Detected
- Infoblox - SOC Insight Detected - API Source
- Infoblox - SOC Insight Detected - API Source
- Infoblox - SOC Insight Detected - CDC Source
- Infoblox - SOC Insight Detected - CDC Source
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains
- Infoblox - TI - Syslog Match Found - URL
- Pathlock TDnR - Bank Master Data Changes
- Pathlock TDnR - Business Partner Bank Data Changes
- Pathlock TDnR - Credit Card Data Changes
- Pathlock TDnR - Debitor Change Documents
- Pathlock TDnR - G/L Account Changes
- Pathlock TDnR - Generic SAP Change Documents
- Pathlock TDnR - Generic Table Content Changes
- Pathlock TDnR - HR User Master Change Requests
- Pathlock TDnR - IBAN Change Documents
- Pathlock TDnR - Payment Request Changes
- Pathlock TDnR - Vendor Change Documents
- Votiro - File Blocked from Connector