Technique with 2 sub-techniques.View on attack.mitre.org
Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.
Rules on DetectionCode tagged with T1491 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Potential Ransomware Activity Using LegalNotice Message | high | windows / registry_set | T1491.001 |
| Potentially Suspicious Desktop Background Change Using Reg.EXE | medium | windows / process_creation | T1491.001 |
| Potentially Suspicious Desktop Background Change Via Registry | medium | windows / registry_set | T1491.001 |
| Replace Desktop Wallpaper by Powershell | low | windows / ps_script | T1491.001 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Modification Of Wallpaper | TTP | NULL | Sysmon EventID 13 | T1491 |
| Windows Defacement Modify Transcodedwallpaper File | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1491 |
None recorded.
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.