1200KM / detection
T1491.001 Internal Defacement — Detection Rules
Detection workspace for T1491.001 Internal Defacement: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Replace Desktop Wallpaper by Powershell · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potentially Suspicious Desktop Background Change Using Reg.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Potentially Suspicious Desktop Background Change Via Registry · test · medium · {"product":"windows","category":"registry_set"}
- Potential Ransomware Activity Using LegalNotice Message · test · high · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0082 Internal Website and System Content Defacement via UI or Messaging Modifications
AN0229 Analytic 0229
Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.
AN0230 Analytic 0230
Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.
AN0231 Analytic 0231
Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript.
AN0232 Analytic 0232
Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.