Cross-source coverage

T1491.001 / ATT&CK

Defacement: Internal Defacement

4 rules across 1 source.

From MITRE ATT&CK 19.2

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.

Tactics
Impact
Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogESXiLogs:messagesesxi:hostd

How MITRE says to detect it DET0082

Internal Website and System Content Defacement via UI or Messaging Modifications

Windows Analytic 0229

Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.

  • WinEventLog:Security EventCode=4663, 4670, 4656
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=2
  • WinEventLog:Sysmon EventCode=1

Linux Analytic 0230

Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.

  • auditd:SYSCALL open/write/unlink
  • auditd:SYSCALL execve
  • linux:syslog sudo or su access prior to content change

macOS Analytic 0231

Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript.

  • macos:unifiedlog loginwindow or desktopservices modified settings or files
  • macos:unifiedlog osascript or AppleScript invocation modifying UI

ESXi Analytic 0232

Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients.

  • ESXiLogs:messages changes to /etc/motd or /etc/vmware/welcome
  • esxi:hostd modification of config files or shell command execution

SigmaHQ/sigma

4 rules
Detection Severity Format
Potential Ransomware Activity Using LegalNotice Message High Sigma
Potentially Suspicious Desktop Background Change Using Reg.EXE Medium Sigma
Potentially Suspicious Desktop Background Change Via Registry Medium Sigma
Replace Desktop Wallpaper by Powershell Low Sigma

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.