{"id":"T1491","name":"Defacement","url":"https://attack.mitre.org/techniques/T1491","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0238","stix_id":"x-mitre-detection-strategy--2d5f2445-a395-4012-b378-c953f2df7353","name":"Defacement via File and Web Content Modification Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0238","analytics":[{"id":"AN0662","stix_id":"x-mitre-analytic--d02dbf1d-b6e9-4c3c-84a2-f70fec797504","name":"Analytic 0662","description":"Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access.","url":"https://attack.mitre.org/detectionstrategies/DET0238#AN0662","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Unexpected web application errors or CMS logs showing modification to index.html, default.aspx, or other public-facing files","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"}],"mutable_elements":[{"field":"target_filenames","description":"Environment-specific naming of defacement-prone files like 'index.html', 'main.css', 'app.js'."},{"field":"TimeWindow","description":"Detection based on rapid sequence of file writes and script injections within short time intervals."}],"live":true,"detection_strategies":["DET0238"],"techniques":["T1491"]},{"id":"AN0663","stix_id":"x-mitre-analytic--7b95ffd7-165d-4435-97b6-4508b9328d89","name":"Analytic 0663","description":"Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services.","url":"https://attack.mitre.org/detectionstrategies/DET0238#AN0663","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"apache:access_log","channel":"Unusual HTTP POST or PUT requests to paths such as '/uploads/', '/admin/', or CMS plugin folders","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"apache-access-log"},{"name":"linux:syslog","channel":"Unauthorized sudo or shell access, especially leading to file changes in /var/www or /srv/http","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"UploadPathRegex","description":"Regex for CMS-specific upload directories subject to defacement (e.g., wp-content/uploads)."},{"field":"FileExtensionScope","description":"Types of files to monitor for defacement (e.g., .html, .php, .jsp)."}],"live":true,"detection_strategies":["DET0238"],"techniques":["T1491"]},{"id":"AN0664","stix_id":"x-mitre-analytic--3258db60-8500-4935-837c-78b23f2d83d1","name":"Analytic 0664","description":"Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs.","url":"https://attack.mitre.org/detectionstrategies/DET0238#AN0664","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of unexpected terminal or web scripts modifying /Library/WebServer/Documents","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"File creation or overwrite in common web-hosting folders","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TargetDirectoryPath","description":"Web root folders will vary depending on how services are configured on macOS (e.g., /Library/WebServer/Documents)."}],"live":true,"detection_strategies":["DET0238"],"techniques":["T1491"]},{"id":"AN0665","stix_id":"x-mitre-analytic--0e7e1861-14be-4862-8cba-6344e6e196f2","name":"Analytic 0665","description":"Adversary defaces internal VM-hosted portals or web UIs by modifying static content on datastore-mounted paths.","url":"https://attack.mitre.org/detectionstrategies/DET0238#AN0665","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"Unauthorized file modifications within datastore volumes via shell access or vCLI","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"DatastoreVolumeName","description":"Each environment’s VMFS/volume mounts will vary in name and path."}],"live":true,"detection_strategies":["DET0238"],"techniques":["T1491"]},{"id":"AN0666","stix_id":"x-mitre-analytic--bd893675-a17e-4c3b-bec4-ffbad6986c73","name":"Analytic 0666","description":"Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets.","url":"https://attack.mitre.org/detectionstrategies/DET0238#AN0666","platforms":["IaaS"],"log_source_references":[{"name":"CloudTrail:PutObject","channel":"PutObject","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"cloudtrail-putobject"},{"name":"AWS:CloudTrail","channel":"GetObject, CopyObject","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"BucketNameRegex","description":"Patterns of S3 or GCP buckets used for static website hosting may vary by organization."},{"field":"IAMRoleContext","description":"Some uploads may appear benign unless enriched with user/role metadata."}],"live":true,"detection_strategies":["DET0238"],"techniques":["T1491"]}],"live":true,"version":"1.0","techniques":["T1491"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}