MITRE ATT&CK technique
Data Manipulation detection rulesT1565
Data Manipulation (T1565) is a MITRE ATT&CK technique in the Impact tactic. This page lists the 11 community-maintained Sigma detection rules in the library mapped to T1565 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target linux, windows, azure.
Commands to Clear or Remove the Syslog - Builtin
highDetects specific commands commonly used to remove or empty the syslog
linux
History File Deletion
highDetects events in which a history file gets deleted, e.g. the ~/bash_history to remove traces of malicious activity
linux · process_creation
Powershell Add Name Resolution Policy Table Rule
highDetects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace. This will bypass the default DNS server and uses a specified server for answering the query.
windows · ps_script
AWS EC2 Disable EBS Encryption
mediumIdentifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.
aws
Azure Device or Configuration Modified or Deleted
mediumIdentifies when a device or device configuration in azure is modified or deleted.
azure
Azure DNS Zone Modified or Deleted
mediumIdentifies when DNS zone is modified or deleted.
azure
Cisco Denial of Service
mediumDetect a system being shutdown or put into different boot mode
cisco
Cisco Modify Configuration
mediumModifications to a config that will serve an adversary's impacts or persistence
cisco
Google Cloud Re-identifies Sensitive Information
mediumIdentifies when sensitive information is re-identified in google Cloud.
gcp
ISATAP Router Address Was Set
mediumDetects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.
windows
Potential Suspicious Change To Sensitive/Critical Files
mediumDetects changes of sensitive and critical files. Monitors files that you don't expect to change without planning on Linux system. These files include, but are not limited to, system configuration files, authentication files, and critical application files. Attackers often target these files to maintain persistence, escalate privileges, or disrupt system operations.
linux · process_creation