T1491.002 - External Defacement
Sub-technique
Tattiche:
Impact
Impact
Piattaforme:
Windows IaaS Linux macOS
Windows IaaS Linux macOS
Rilevamento:
Not specified
Not specified
Description:
An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. [External Defacement](https://attack.mitre.org/techniques/T1491/002) may ultimately cause users to distrust the systems and to question/discredit the system’s integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda.(Citation: FireEye Cyber Threats to Media Industries)(Citation: Kevin Mandia Statement to US Senate Committee on Intelligence)(Citation: Anonymous Hackers Deface Russian Govt Site) [External Defacement](https://attack.mitre.org/techniques/T1491/002) may be used as a catalyst to trigger events, or as a response to actions taken by an organization or government. Similarly, website defacement may also be used as setup, or a precursor, for future attacks such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189).(Citation: Trend Micro Deep Dive Into Defacement)
Usato da Attori (2)
Metadata
| MITRE ID: | T1491.002 |
| STIX ID: | attack-pattern--0cfe31a7-81fc-... |
| Piattaforme: | Windows, IaaS, Linux, macOS |
| Created: | 13/01/2026 17:48 |
| Updated: | 14/03/2026 04:00 |