Defacement: External Defacement T1491.002
Tactic: Impact
An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may ultimately cause users to distrust the systems and to question/discredit the system’s integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda. External Defacement may be used as a catalyst to trigger events, or as a response to actions taken by an organization or government. Similarly, website defacement may also be used as setup, or a precursor, for future attacks such as Drive-by Compromise.
Authoring guide
These 1 rule share fields, values, and exclusions.
Fields filtered most (7 distinct)
These fields appear most often in rule filters.
Top indicator values (8 distinct)
These values appear most often in rule predicates.
Exclusions (3 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: AWS
Domain: Cloud