Stored Data Manipulation

T1565.001

Sub-technique of T1565 Data Manipulation.View on attack.mitre.org

About this technique

Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making.

Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The type of modification and the impact it will have depends on the type of data as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.

Detection rules7

Rules on DetectionCode tagged with T1565.001.

Sigma6

RuleLevelLog source
Commands to Clear or Remove the Syslog - Builtinhighlinux / NULL
History File Deletionhighlinux / process_creation
Azure Device or Configuration Modified or Deletedmediumazure / NULL
Azure DNS Zone Modified or Deletedmediumazure / NULL
Cisco Denial of Servicemediumcisco / NULL
Potential Suspicious Change To Sensitive/Critical Filesmediumlinux / process_creation

Splunk1

RuleTypeRiskData source
Windows WBAdmin File Recovery From BackupAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups1

Software2

Campaigns0

None recorded.

Procedure examples3

Groups1

Used byProcedure example
GroupAPT38

APT38 has used DYEPACK to create, delete, and alter records in databases used for SWIFT transactions.

Software2

Used byProcedure example
MalwareMultiLayer Wiper

MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult.

MalwareSUNSPOT

SUNSPOT created a copy of the SolarWinds Orion software source file with a .bk extension to backup the original content, wrote SUNBURST using the same filename but with a .tmp extension, and then moved SUNBURST using MoveFileEx to the original filename with a .cs extension so it could be compiled within Orion software.

References2

  1. DOJ Lazarus Sony 2018 Open source
    Department of Justice. (2018, September 6). Criminal Complaint - United States of America v. PARK JIN HYOK. Retrieved March 29, 2019.
  2. FireEye APT38 Oct 2018 Open source
    FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.