kevmap

TechniquesT1491 › T1491.001

T1491.001 Internal Defacement

impact — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
4
Sigma rules tagged attack.t1491.001
0
KEV CVEs mapped here
<p>An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1491.001

Author: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ) · 2023-12-21 (modified 2025-10-17) · logsource: product=windows category=registry_set · 85b88e05-dadc-430b-8a9e-53ff1cd30aae
Detects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
Techniques: T1112T1491.001
Author: frack113 · 2022-12-11 (modified 2023-08-17) · logsource: product=windows category=registry_set · 8b9606c9-28be-4a38-b146-0e313cc232c1
Detect changes to the "LegalNoticeCaption" or "LegalNoticeText" registry values where the message set contains keywords often used in ransomware ransom messages
Techniques: T1491.001
Author: Stephen Lincoln @slincoln-aiq (AttackIQ) · 2023-12-21 · logsource: product=windows category=process_creation · 8cbc9475-8d05-4e27-9c32-df960716c701
Detects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
Techniques: T1112T1491.001
Author: frack113 · 2021-12-26 · logsource: product=windows category=ps_script · c5ac6a1e-9407-45f5-a0ce-ca9a0806a287
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users. This may take the form of modifications to internal websites, or directly to user systems with the replacement of the desktop wallpaper
Techniques: T1491.001