{"id":"T1056.003","name":"Web Portal Capture","url":"https://attack.mitre.org/techniques/T1056/003","tactics":["collection","credential-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0480","stix_id":"x-mitre-detection-strategy--8b2a91cd-4a15-4b25-9b75-581298f3ef82","name":"Detection of Credential Harvesting via Web Portal Modification","url":"https://attack.mitre.org/detectionstrategies/DET0480","analytics":[{"id":"AN1320","stix_id":"x-mitre-analytic--5233d621-6658-4338-b183-01bd73e52861","name":"Analytic 1320","description":"Detects unauthorized modifications to login-facing web server files (e.g., index.php, login.js) typically tied to VPN, SSO, or intranet portals. Correlates suspicious file changes with remote access artifacts or web shell behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0480#AN1320","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"HTTP Request Logging","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredFilePaths","description":"Target login-related files (e.g., /var/www/html/login.php) for integrity monitoring"},{"field":"TimeWindow","description":"Tune detection to correlate file edits and web access within a short duration"}],"live":true,"detection_strategies":["DET0480"],"techniques":["T1056.003"]},{"id":"AN1321","stix_id":"x-mitre-analytic--4f33b538-1370-4df1-934f-fe3a609453fb","name":"Analytic 1321","description":"Detects tampering of IIS-based login pages (e.g., default.aspx, login.aspx) tied to VPN, OWA, or SharePoint via script injection or unexpected editor processes modifying web roots.","url":"https://attack.mitre.org/detectionstrategies/DET0480#AN1321","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:iis","channel":"IIS Logs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"wineventlog-iis"}],"mutable_elements":[{"field":"FilePath","description":"Define path to monitored IIS web root (e.g., C:\\inetpub\\wwwroot\\login.aspx)"},{"field":"ProcessName","description":"Exclude legitimate updates (e.g., msdeploy.exe) and alert on suspicious editors (e.g., notepad.exe, certutil.exe)"}],"live":true,"detection_strategies":["DET0480"],"techniques":["T1056.003"]},{"id":"AN1322","stix_id":"x-mitre-analytic--564071d9-44b1-44b8-92c0-348e22e544b7","name":"Analytic 1322","description":"Detects unauthorized changes to locally hosted login pages on macOS (common in developer VPN environments) and links file edits to cron jobs, background scripts, or SUID binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0480#AN1322","platforms":["macOS"],"log_source_references":[{"name":"fs:fsusage","channel":"Filesystem Access Logging","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-fsusage"},{"name":"macos:unifiedlog","channel":"subsystem=com.apple.WebKit","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WebRootPath","description":"Specify custom web service directories (e.g., /Library/WebServer/Documents/)"},{"field":"AnomalousProcess","description":"Alert on web root changes from non-web processes or scripts"}],"live":true,"detection_strategies":["DET0480"],"techniques":["T1056.003"]}],"live":true,"version":"1.0","techniques":["T1056.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}