Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.
Adversary defaces internal VM-hosted portals or web UIs by modifying static content on datastore-mounted paths.
Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs.
Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services.