{"id":"T1491.002","name":"External Defacement","url":"https://attack.mitre.org/techniques/T1491/002","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0590","stix_id":"x-mitre-detection-strategy--33bbfada-99c8-4cac-8b21-fa013959001d","name":"Behavioral Detection of External Website Defacement across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0590","analytics":[{"id":"AN1622","stix_id":"x-mitre-analytic--67febd8b-36fe-4f72-8647-95fe449ecb5d","name":"Analytic 1622","description":"Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities.","url":"https://attack.mitre.org/detectionstrategies/DET0590#AN1622","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-security"},{"name":"NSM:Connections","channel":"Unusual POST requests to admin or upload endpoints","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-connections"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"target_directory","description":"Web root folder varies by environment, e.g., C:\\inetpub\\wwwroot"},{"field":"UserContext","description":"May vary based on which service account hosts the website"},{"field":"TimeWindow","description":"Time between webshell upload and file overwrite may vary"}],"live":true,"detection_strategies":["DET0590"],"techniques":["T1491.002"]},{"id":"AN1623","stix_id":"x-mitre-analytic--1affb8e9-25b4-49c1-b290-687e9696fa83","name":"Analytic 1623","description":"Adversary compromises a Linux-based web server and modifies hosted web files by exploiting upload vulnerabilities, remote code execution, or replacing index.html via SSH/webshell.","url":"https://attack.mitre.org/detectionstrategies/DET0590#AN1623","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/write syscalls targeting web directory files","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"NSM:Connections","channel":"Successful sudo or ssh from unknown IPs","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"nsm-connections"},{"name":"NSM:Flow","channel":"Suspicious POSTs to upload endpoints","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"web_root","description":"May differ (e.g., /var/www/html, /srv/http, etc.)"},{"field":"payload_hash","description":"Adversary content hash may change across campaigns"},{"field":"UserContext","description":"Can range from apache/nginx user to root if escalated"}],"live":true,"detection_strategies":["DET0590"],"techniques":["T1491.002"]},{"id":"AN1624","stix_id":"x-mitre-analytic--c9b3d194-843a-4f65-ad8b-4b3192571fc5","name":"Analytic 1624","description":"Adversary modifies web-facing content on macOS via web development environments like MAMP or misconfigured Apache instances, typically with access to the hosting user account or via persistence tools.","url":"https://attack.mitre.org/detectionstrategies/DET0590#AN1624","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Terminal/Editor processes modifying web folder","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"loginwindow or sshd events with external IP","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"web_root_dir","description":"May include ~/Sites or custom Apache paths"},{"field":"editor_name","description":"Text editor or script modifying the files may vary (e.g., nano, VS Code)"}],"live":true,"detection_strategies":["DET0590"],"techniques":["T1491.002"]},{"id":"AN1625","stix_id":"x-mitre-analytic--afd585f3-20fa-4bd8-8930-243cb5dbe5f8","name":"Analytic 1625","description":"Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.","url":"https://attack.mitre.org/detectionstrategies/DET0590#AN1625","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"PutObject","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"ListBuckets","data_component":"DC0017","data_component_name":"Cloud Storage Enumeration","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"GetObject, CopyObject","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"bucket_name","description":"Website bucket name varies per org"},{"field":"region","description":"Adversary may target multi-region failover setups"},{"field":"IAMRole","description":"Attack may leverage stolen cross-account roles or elevated policies"}],"live":true,"detection_strategies":["DET0590"],"techniques":["T1491.002"]}],"live":true,"version":"1.0","techniques":["T1491.002"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2018-15961","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}