// MITRE ATT&CK

T1491.001 · Internal Defacement

🎯 Impact ESXiLinuxmacOSWindows Sub-técnica

Sub-técnica de T1491 · Defacement.

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the des...

¿Cómo detectarlo y mitigarlo?

La detección de Internal Defacement parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.