{"id":"T1565.002","name":"Transmitted Data Manipulation","url":"https://attack.mitre.org/techniques/T1565/002","tactics":["impact"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0254","stix_id":"x-mitre-detection-strategy--1764bbd5-67d1-4225-9c06-0d5aa74d056f","name":"Detection Strategy of Transmitted Data Manipulation","url":"https://attack.mitre.org/detectionstrategies/DET0254","analytics":[{"id":"AN0702","stix_id":"x-mitre-analytic--4cf44d48-1a0f-45a4-9a25-8bee9677ab52","name":"Analytic 0702","description":"Monitor for anomalies in transmitted data streams, including mismatched file integrity checks, API interception, or man-in-the-middle modifications. Detect unexpected use of APIs that handle network I/O where transmitted data integrity could be manipulated.","url":"https://attack.mitre.org/detectionstrategies/DET0254#AN0702","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"IntegrityBaseline","description":"Hash baselines or digital signature references to validate transmitted data."},{"field":"MonitoredPorts","description":"List of ports/services where data integrity validation is enforced."}],"live":true,"detection_strategies":["DET0254"],"techniques":["T1565.002"]},{"id":"AN0703","stix_id":"x-mitre-analytic--500ae9f9-c6c2-4160-ac03-072d963eba63","name":"Analytic 0703","description":"Detect alterations of transmitted data via monitoring syscalls (`send`, `recv`, `write`) or middleware interception. Identify mismatched file hashes when compared at origin vs. destination. Watch for anomalous activity from processes interacting with secure transmission services (e.g., OpenSSL, scp).","url":"https://attack.mitre.org/detectionstrategies/DET0254#AN0703","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"send, recv, write: Abnormal interception or alteration of transmitted data","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Integrity mismatch warnings or malformed packets detected","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"WatchedProcesses","description":"List of processes authorized to handle transmitted data (e.g., sshd, nginx)."},{"field":"HashCheckInterval","description":"Frequency of out-of-band integrity verification checks."}],"live":true,"detection_strategies":["DET0254"],"techniques":["T1565.002"]},{"id":"AN0704","stix_id":"x-mitre-analytic--da6d7de2-a666-4fa3-aa53-54692a8167ae","name":"Analytic 0704","description":"Monitor system APIs such as CFNetwork and SecureTransport for anomalies in transmitted data streams. Detect mismatches in file hashes or SSL/TLS downgrade attempts that enable manipulation of transmitted data.","url":"https://attack.mitre.org/detectionstrategies/DET0254#AN0704","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Suspicious anomalies in transmitted data integrity during application network operations","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"CALCULATE: Integrity validation of transmitted data via hash checks","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"TLSValidationRules","description":"Custom rules for enforcing HTTPS/TLS integrity checks to prevent downgrade manipulation."},{"field":"AllowedApps","description":"Whitelisted macOS apps permitted to transmit critical data."}],"live":true,"detection_strategies":["DET0254"],"techniques":["T1565.002"]}],"live":true,"version":"1.0","techniques":["T1565.002"]}],"sigma_rules":[{"id":"671ffc77-50a7-464f-9e3d-9ea2b493b26b","title":"Cisco Modify Configuration","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-12","modified":"2025-04-28","description":"Modifications to a config that will serve an adversary's impacts or persistence","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.impact","attack.t1490","attack.t1505","attack.t1565.002","attack.t1053"],"path":"rules/network/cisco/aaa/cisco_cli_modify_config.yml","techniques":["T1490","T1505","T1565.002","T1053"],"cves":[]},{"id":"d22df9cd-2aee-4089-93c7-9dc4eae77f2c","title":"ISATAP Router Address Was Set","author":"hamid","status":"experimental","level":"medium","date":"2025-10-19","modified":null,"description":"Detects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6.\nIn such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic.\nThis detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.\n","references":["https://www.blackhillsinfosec.com/mitm6-strikes-again-the-dark-side-of-ipv6/","https://redfoxsec.com/blog/ipv6-dns-takeover/","https://www.securityhq.com/blog/malicious-isatap-tunneling-unearthed-on-windows-server/","https://medium.com/@ninnesoturan/detecting-ipv6-dns-takeover-a54a6a88be1f"],"logsource":{"product":"windows","service":"system"},"tags":["attack.impact","attack.credential-access","attack.collection","attack.initial-access","attack.privilege-escalation","attack.execution","attack.t1557","attack.t1565.002"],"path":"rules/windows/builtin/system/microsoft_windows_Iphlpsvc/win_system_isatap_router_address_set.yml","techniques":["T1557","T1565.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}