Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0082 — Internal Website and System Content Defacement via UI or Messaging Modifications
DET0082

Internal Website and System Content Defacement via UI or Messaging Modifications

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0229 Analytic 0229
Windows

Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=2 WinEventLog:Sysmon EventCode=1
[FilePathPattern] Location of web content or system UI config files that may vary across deployments (e.g., %SystemRoot%\Web, %APPDATA%\wallpaper.jpg)
[TimeWindow] Allowed hours for file/content modification events; defacement likely occurs during off-hours
[UserContext] System or domain accounts used to perform the modifications may be anomalous
AN0230 Analytic 0230
Linux

Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.

auditd:SYSCALL open/write/unlink auditd:SYSCALL execve linux:syslog sudo or su access prior to content change
[TargetDirectories] Paths like /var/www/html, /etc/issue, or /etc/motd may vary across distros
[UserContext] Non-web-admin users modifying site content or banners should be rare
[TimeWindow] Defacement often happens outside normal maintenance hours
AN0231 Analytic 0231
macOS

Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript.

macos:unifiedlog loginwindow or desktopservices modified settings or files macos:unifiedlog osascript or AppleScript invocation modifying UI
[ScriptNames] Uncommon scripts like AppleScript variants or osascript for wallpaper changes
[UserContext] Normal users should not alter global visual settings
AN0232 Analytic 0232
ESXi

Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients.

ESXiLogs:messages changes to /etc/motd or /etc/vmware/welcome esxi:hostd modification of config files or shell command execution
[LoginBannerFilePath] Target file paths (e.g., /etc/motd) may be changed via symbolic link or override
[AccessOrigin] ESXi hostd vs. SSH-based defacement origin may affect visibility

Detected Techniques

1

Details

MITRE ID
DET0082
STIX ID
x-mitre-detection-strategy--c8b4a2e4-386f-45b3-b32a-8ca4113e5592
Analytics
4
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.