1200KM / detection
T1565 Data Manipulation — Detection Rules
Detection workspace for T1565 Data Manipulation: 3 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS EC2 Disable EBS Encryption · stable · medium · {"product":"aws","service":"cloudtrail"}
- Google Cloud Re-identifies Sensitive Information · test · medium · {"product":"gcp","service":"gcp.audit"}
- Powershell Add Name Resolution Policy Table Rule · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
Atlas deterministic concepts
T1565 Data Manipulation
MATCH(update_or_delete_on_protected_record) AND actor NOT_IN approved_writers -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0059 Detection Strategy for Data Manipulation
AN0162 Analytic 0162
Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.
AN0163 Analytic 0163
Detect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns.
AN0164 Analytic 0164
Detect manipulation of system or application files in `/Library`, `/System`, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Network Traffic Content · DC0085
- OS API Execution · DC0021
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.