T1491.001 Internal Defacement
Sub-technique of T1491 Defacement
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper.(Citation: Novetta Blockbuster)(Citation: Varonis) Disturbing or offensive images…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential Ransomware Activity Using LegalNotice Messagehightest · windows
- Potentially Suspicious Desktop Background Change Using Reg.EXEmediumtest · windows
- Potentially Suspicious Desktop Background Change Via Registrymediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.