{"id":"T1491.001","name":"Internal Defacement","url":"https://attack.mitre.org/techniques/T1491/001","tactics":["impact"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0082","stix_id":"x-mitre-detection-strategy--c8b4a2e4-386f-45b3-b32a-8ca4113e5592","name":"Internal Website and System Content Defacement via UI or Messaging Modifications","url":"https://attack.mitre.org/detectionstrategies/DET0082","analytics":[{"id":"AN0229","stix_id":"x-mitre-analytic--78c505c6-25a1-4cc5-b44a-0574aa019f01","name":"Analytic 0229","description":"Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.","url":"https://attack.mitre.org/detectionstrategies/DET0082#AN0229","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"FilePathPattern","description":"Location of web content or system UI config files that may vary across deployments (e.g., %SystemRoot%\\Web, %APPDATA%\\wallpaper.jpg)"},{"field":"TimeWindow","description":"Allowed hours for file/content modification events; defacement likely occurs during off-hours"},{"field":"UserContext","description":"System or domain accounts used to perform the modifications may be anomalous"}],"live":true,"detection_strategies":["DET0082"],"techniques":["T1491.001"]},{"id":"AN0230","stix_id":"x-mitre-analytic--8ba0c3e2-9544-47d1-9738-757c35dc19fa","name":"Analytic 0230","description":"Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.","url":"https://attack.mitre.org/detectionstrategies/DET0082#AN0230","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/write/unlink","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"sudo or su access prior to content change","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"TargetDirectories","description":"Paths like /var/www/html, /etc/issue, or /etc/motd may vary across distros"},{"field":"UserContext","description":"Non-web-admin users modifying site content or banners should be rare"},{"field":"TimeWindow","description":"Defacement often happens outside normal maintenance hours"}],"live":true,"detection_strategies":["DET0082"],"techniques":["T1491.001"]},{"id":"AN0231","stix_id":"x-mitre-analytic--83d3222d-6a35-401d-95b5-a09f0eac2201","name":"Analytic 0231","description":"Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript.","url":"https://attack.mitre.org/detectionstrategies/DET0082#AN0231","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"loginwindow or desktopservices modified settings or files","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"osascript or AppleScript invocation modifying UI","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ScriptNames","description":"Uncommon scripts like AppleScript variants or osascript for wallpaper changes"},{"field":"UserContext","description":"Normal users should not alter global visual settings"}],"live":true,"detection_strategies":["DET0082"],"techniques":["T1491.001"]},{"id":"AN0232","stix_id":"x-mitre-analytic--c024ed9a-02bf-436d-93f5-444e45124e2f","name":"Analytic 0232","description":"Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients.","url":"https://attack.mitre.org/detectionstrategies/DET0082#AN0232","platforms":["ESXi"],"log_source_references":[{"name":"ESXiLogs:messages","channel":"changes to /etc/motd or /etc/vmware/welcome","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"esxilogs-messages"},{"name":"esxi:hostd","channel":"modification of config files or shell command execution","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"LoginBannerFilePath","description":"Target file paths (e.g., /etc/motd) may be changed via symbolic link or override"},{"field":"AccessOrigin","description":"ESXi hostd vs. SSH-based defacement origin may affect visibility"}],"live":true,"detection_strategies":["DET0082"],"techniques":["T1491.001"]}],"live":true,"version":"1.0","techniques":["T1491.001"]}],"sigma_rules":[{"id":"85b88e05-dadc-430b-8a9e-53ff1cd30aae","title":"Potentially Suspicious Desktop Background Change Via Registry","author":"Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ)","status":"test","level":"medium","date":"2023-12-21","modified":"2025-10-17","description":"Detects registry value settings that would replace the user's desktop background.\nThis is a common technique used by malware to change the desktop background to a ransom note or other image.\n","references":["https://www.attackiq.com/2023/09/20/emulating-rhysida/","https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/","https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html","https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior","https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper","https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.impact","attack.defense-impairment","attack.t1112","attack.t1491.001"],"path":"rules/windows/registry/registry_set/registry_set_desktop_background_change.yml","techniques":["T1112","T1491.001"],"cves":[]},{"id":"8b9606c9-28be-4a38-b146-0e313cc232c1","title":"Potential Ransomware Activity Using LegalNotice Message","author":"frack113","status":"test","level":"high","date":"2022-12-11","modified":"2023-08-17","description":"Detect changes to the \"LegalNoticeCaption\" or \"LegalNoticeText\" registry values where the message set contains keywords often used in ransomware ransom messages","references":["https://github.com/redcanaryco/atomic-red-team/blob/5c1e6f1b4fafd01c8d1ece85f510160fc1275fbf/atomics/T1491.001/T1491.001.md"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.impact","attack.t1491.001"],"path":"rules/windows/registry/registry_set/registry_set_legalnotice_susp_message.yml","techniques":["T1491.001"],"cves":[]},{"id":"8cbc9475-8d05-4e27-9c32-df960716c701","title":"Potentially Suspicious Desktop Background Change Using Reg.EXE","author":"Stephen Lincoln @slincoln-aiq (AttackIQ)","status":"test","level":"medium","date":"2023-12-21","modified":null,"description":"Detects the execution of \"reg.exe\" to alter registry keys that would replace the user's desktop background.\nThis is a common technique used by malware to change the desktop background to a ransom note or other image.\n","references":["https://www.attackiq.com/2023/09/20/emulating-rhysida/","https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/","https://www.trendmicro.com/en_us/research/23/h/an-overview-of-the-new-rhysida-ransomware.html","https://www.virustotal.com/gui/file/a864282fea5a536510ae86c77ce46f7827687783628e4f2ceb5bf2c41b8cd3c6/behavior","https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsDesktop::Wallpaper","https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ControlPanelDisplay::CPL_Personalization_NoDesktopBackgroundUI"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.impact","attack.defense-impairment","attack.t1112","attack.t1491.001"],"path":"rules/windows/process_creation/proc_creation_win_reg_desktop_background_change.yml","techniques":["T1112","T1491.001"],"cves":[]},{"id":"c5ac6a1e-9407-45f5-a0ce-ca9a0806a287","title":"Replace Desktop Wallpaper by Powershell","author":"frack113","status":"test","level":"low","date":"2021-12-26","modified":null,"description":"An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users.\nThis may take the form of modifications to internal websites, or directly to user systems with the replacement of the desktop wallpaper\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1491.001/T1491.001.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.impact","attack.t1491.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_wallpaper.yml","techniques":["T1491.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}