Cross-source coverage
T1491.001 / ATT&CK
Defacement: Internal Defacement
4 rules across 1 source.
From MITRE ATT&CK 19.2
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.
- Tactics
- Impact
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogESXiLogs:messagesesxi:hostd
How MITRE says to detect it DET0082
Internal Website and System Content Defacement via UI or Messaging Modifications
Windows Analytic 0229
Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.
WinEventLog:SecurityEventCode=4663, 4670, 4656WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=2WinEventLog:SysmonEventCode=1
Linux Analytic 0230
Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.
auditd:SYSCALLopen/write/unlinkauditd:SYSCALLexecvelinux:syslogsudo or su access prior to content change
macOS Analytic 0231
Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript.
macos:unifiedlogloginwindow or desktopservices modified settings or filesmacos:unifiedlogosascript or AppleScript invocation modifying UI
ESXi Analytic 0232
Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients.
ESXiLogs:messageschanges to /etc/motd or /etc/vmware/welcomeesxi:hostdmodification of config files or shell command execution
SigmaHQ/sigma
4 rules| Detection | Severity | Format |
|---|---|---|
| Potential Ransomware Activity Using LegalNotice Message | High | Sigma |
| Potentially Suspicious Desktop Background Change Using Reg.EXE | Medium | Sigma |
| Potentially Suspicious Desktop Background Change Via Registry | Medium | Sigma |
| Replace Desktop Wallpaper by Powershell | Low | Sigma |