{"id":"T1565","name":"Data Manipulation","url":"https://attack.mitre.org/techniques/T1565","tactics":["impact"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0059","stix_id":"x-mitre-detection-strategy--cce3ccaf-87ac-47ae-b9e2-6507b91cb63d","name":"Detection Strategy for Data Manipulation","url":"https://attack.mitre.org/detectionstrategies/DET0059","analytics":[{"id":"AN0162","stix_id":"x-mitre-analytic--64d6b35c-4785-4e2b-bc93-1f54f626a7a7","name":"Analytic 0162","description":"Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.","url":"https://attack.mitre.org/detectionstrategies/DET0059#AN0162","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=2","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"MonitoredFilePaths","description":"List of critical data directories or files; environment-specific tuning required."},{"field":"TimeWindow","description":"Threshold for correlating process execution with rapid data changes."},{"field":"AuthorizedProcesses","description":"Expected processes permitted to modify business-critical data."}],"live":true,"detection_strategies":["DET0059"],"techniques":["T1565"]},{"id":"AN0163","stix_id":"x-mitre-analytic--2e700f3b-bf9c-427c-a099-b80d233c1ccb","name":"Analytic 0163","description":"Detect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0059#AN0163","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, unlink, rename: Suspicious file access, deletion, or modification of sensitive paths","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Unexpected SQL or application log entries showing tampered or malformed data","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"WatchedDirectories","description":"Specific log or data directories critical to integrity; tune per organization."},{"field":"CommandExclusions","description":"Legitimate scripts/tools excluded from data manipulation monitoring."}],"live":true,"detection_strategies":["DET0059"],"techniques":["T1565"]},{"id":"AN0164","stix_id":"x-mitre-analytic--13f8d339-8239-4d84-adf2-1abf1a0f3d5d","name":"Analytic 0164","description":"Detect manipulation of system or application files in `/Library`, `/System`, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.","url":"https://attack.mitre.org/detectionstrategies/DET0059#AN0164","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Anomalous plist modifications or sensitive file overwrites by non-standard processes","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"open, execve: Unexpected processes accessing or modifying critical files","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"AllowedPlistEditors","description":"Whitelisted processes authorized to modify plist or configuration files."},{"field":"FileIntegrityBaseline","description":"Baseline hash values for key files to support integrity validation."}],"live":true,"detection_strategies":["DET0059"],"techniques":["T1565"]}],"live":true,"version":"1.0","techniques":["T1565"]}],"sigma_rules":[{"id":"16124c2d-e40b-4fcc-8f2c-5ab7870a2223","title":"AWS EC2 Disable EBS Encryption","author":"Sittikorn S","status":"stable","level":"medium","date":"2021-06-29","modified":"2021-08-20","description":"Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region.\nDisabling default encryption does not change the encryption status of your existing volumes.\n","references":["https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DisableEbsEncryptionByDefault.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.impact","attack.t1486","attack.t1565"],"path":"rules/cloud/aws/cloudtrail/aws_ec2_disable_encryption.yml","techniques":["T1486","T1565"],"cves":[]},{"id":"234f9f48-904b-4736-a34c-55d23919e4b7","title":"Google Cloud Re-identifies Sensitive Information","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-15","modified":"2022-10-09","description":"Identifies when sensitive information is re-identified in google Cloud.","references":["https://cloud.google.com/dlp/docs/reference/rest/v2/projects.content/reidentify"],"logsource":{"product":"gcp","service":"gcp.audit"},"tags":["attack.impact","attack.t1565"],"path":"rules/cloud/gcp/audit/gcp_dlp_re_identifies_sensitive_information.yml","techniques":["T1565"],"cves":[]},{"id":"4368354e-1797-463c-bc39-a309effbe8d7","title":"Powershell Add Name Resolution Policy Table Rule","author":"Borna Talebi","status":"test","level":"high","date":"2021-09-14","modified":"2022-10-09","description":"Detects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace.\nThis will bypass the default DNS server and uses a specified server for answering the query.\n","references":["https://twitter.com/NathanMcNulty/status/1569497348841287681","https://learn.microsoft.com/en-us/powershell/module/dnsclient/add-dnsclientnrptrule?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.impact","attack.t1565"],"path":"rules/windows/powershell/powershell_script/posh_ps_add_dnsclient_rule.yml","techniques":["T1565"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-24993","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-31207","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}