Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering messaging, intimidation, or claiming (possibly false) credit for an intrusion. Disturbing or offensive images may be used as a part of Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages.
View in MITRE ATT&CK®| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| attribute.availability.variety.Obscuration | Conversion or obscuration (ransomware) | related-to | T1491 | Defacement | |
| attribute.integrity.variety.Defacement | Deface content | related-to | T1491 | Defacement |
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| backup_and_dr_actifiogo | Backup and DR-Actifio GO | technique_scores | T1491 | Defacement |
Comments
Backup and DR-Actifio GO is a copy data management plaform that virtualizes application data to improve an organizations resiliency and cloud mobility. This capability allows an organization to take regular backups and provides several methods of restoring applications and/or VM data to a previous state. This provides significant ability to respond to Defacement since an organization could easily restore defaced images back to the latest backup.
References
|
| Technique ID | Technique Name | Number of Mappings |
|---|---|---|
| T1491.002 | External Defacement | 2 |
| T1491.001 | Internal Defacement | 2 |