Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1491 — Defacement
T1491

Defacement

Impact
TLP:CLEAR

Description

Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.

MITRE ATT&CK Detection Strategies
1

DET0238 Defacement via File and Web Content Modification Across Platforms
AN0665 ESXi

Adversary defaces internal VM-hosted portals or web UIs by modifying static content on datastore-mounted paths.

esxi:vmkernel
AN0664 macOS

Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs.

macos:unifiedlog macos:unifiedlog
AN0663 Linux

Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services.

auditd:SYSCALL apache:access_log linux:syslog
+2 more analytics

MITRE ATT&CK Mitigations
1

M1053

Data Backup

Data Backup involves taking and securely storing backups of data from end-user systems and critical servers. It ensures that data remains available in the event of system compromise, ransomware attacks, or other disruptions. Backup processes should include hardening backup systems, implementing secure storage solutions, and keeping backups isolated from the corporate network to prevent compromise during active incidents. This mitigation can be implemented through the following measures: Regular Backup Scheduling: - Use Case: Ensure timely and consistent backups of critical data. - Implementation: Schedule daily incremental backups and weekly full backups for all critical servers and systems. Immutable Backups: - Use Case: Protect backups from modification or deletion, even by attackers. - Implementation: Use write-once-read-many (WORM) storage for backups, preventing ransomware from encrypting or deleting backup files. Backup Encryption: - Use Case: Protect data integrity and confidentiality during transit and storage. - Implementation: Encrypt backups using strong encryption protocols (e.g., AES-256) before storing them in local, cloud, or remote locations. Offsite Backup Storage: - Use Case: Ensure data availability during physical disasters or onsite breaches. - Implementation: Use cloud-based solutions like AWS S3, Azure Backup, or physical offsite storage to maintain a copy of critical data. Backup Testing: - Use Case: Validate backup integrity and ensure recoverability. - Implementation: Regularly test data restoration processes to ensure that backups are not corrupted and can be recovered quickly.

Details

Platforms
Windows
Iaas
Linux
Macos
Esxi
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.