kevmap

TechniquesT1491.002 › AN1625

AN1625 Analytic 1625

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.</p>
Detects
T1491.002 External Defacement
Part of
DET0590 Behavioral Detection of External Website Defacement across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailPutObjectDC0039 File Creation
AWS:CloudTrailListBucketsDC0017 Cloud Storage Enumeration
AWS:CloudTrailGetObject, CopyObjectDC0025 Cloud Storage Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
bucket_nameWebsite bucket name varies per org
regionAdversary may target multi-region failover setups
IAMRoleAttack may leverage stolen cross-account roles or elevated policies

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2018-15961Adobe ColdFusionMapped