1200KM / simulation
T1491.001 Internal Defacement — Attack Simulation
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure…
Technique description
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Windows - Display a simulated ransom note via Notepad (non-destructive)
Procedure 0eeb68ce-e64c-4420-8d53-ad5bdc6f86d5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Replace Desktop Wallpaper
Procedure 30558d53-9d76-41c4-9267-a7bd5184bed3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- ESXi - Change Welcome Message on Direct Console User Interface (DCUI)
Procedure 30905f21-34f3-4504-8b4c-f7a5e314b810; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Configure LegalNoticeCaption and LegalNoticeText registry keys to display ransom message
Procedure ffcbfaab-c9ff-470b-928c-f086b326089b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.