1200KM / detection
T1491.002 External Defacement — Detection Rules
Detection workspace for T1491.002 External Defacement: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0590 Behavioral Detection of External Website Defacement across Platforms
AN1622 Analytic 1622
Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities.
AN1623 Analytic 1623
Adversary compromises a Linux-based web server and modifies hosted web files by exploiting upload vulnerabilities, remote code execution, or replacing index.html via SSH/webshell.
AN1624 Analytic 1624
Adversary modifies web-facing content on macOS via web development environments like MAMP or misconfigured Apache instances, typically with access to the hosting user account or via persistence tools.
AN1625 Analytic 1625
Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1491.002 simulation workspace
- Cloud Storage Access · DC0025
- Cloud Storage Enumeration · DC0017
- File Creation · DC0039
- File Modification · DC0061
- Logon Session Metadata · DC0088
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.