1200KM / detection
T1491 Defacement — Detection Rules
Detection workspace for T1491 Defacement: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0238 Defacement via File and Web Content Modification Across Platforms
AN0662 Analytic 0662
Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access.
AN0663 Analytic 0663
Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services.
AN0664 Analytic 0664
Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs.
AN0665 Analytic 0665
Adversary defaces internal VM-hosted portals or web UIs by modifying static content on datastore-mounted paths.
AN0666 Analytic 0666
Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Cloud Storage Access · DC0025
- File Creation · DC0039
- File Modification · DC0061
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.