Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.
The type of modification and the impact it will have depends on the target application and process as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.
Rules on DetectionCode tagged with T1565 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Commands to Clear or Remove the Syslog - Builtin | high | linux / NULL | T1565.001 |
| History File Deletion | high | linux / process_creation | T1565.001 |
| Powershell Add Name Resolution Policy Table Rule | high | windows / ps_script | T1565 |
| AWS EC2 Disable EBS Encryption | medium | aws / NULL | T1565 |
| Azure Device or Configuration Modified or Deleted | medium | azure / NULL | T1565.001 |
| Azure DNS Zone Modified or Deleted | medium | azure / NULL | T1565.001 |
| Cisco Denial of Service | medium | cisco / NULL | T1565.001 |
| Cisco Modify Configuration | medium | cisco / NULL | T1565.002 |
| Google Cloud Re-identifies Sensitive Information | medium | gcp / NULL | T1565 |
| ISATAP Router Address Was Set | medium | windows / NULL | T1565.002 |
| Potential Suspicious Change To Sensitive/Critical Files | medium | linux / process_creation | T1565.001 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Windows WBAdmin File Recovery From Backup | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1565.001 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupFIN13 | FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.