LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1491.001: Internal Defacement

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper.[1][2] Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.[3]

EnterpriseT1491.001Sub-techniqueObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Internal Defacement is an impact behavior where an intruder changes content seen by employees or internal users, such as internal websites, server login messages, or desktop wallpaper. For leaders, this matters because it is usually a visible signal that system integrity has been lost and may create confusion, intimidation, reputational pressure, or operational disruption inside the organization.

Executive priority

Treat internal defacement as more than a cosmetic incident. Because ATT&CK notes it often occurs after other intrusion goals have been accomplished, leadership should ask whether the visible message is a distraction from broader compromise, ransomware, wiper activity, or data-impact operations. Priority decisions should focus on incident containment, integrity validation, employee communications, restoration readiness, and evidence that backups and critical internal platforms can be recovered safely.

Technical view

SOC and IR teams should validate monitoring across Windows, Linux, macOS, and ESXi environments for unauthorized changes to internal web content, login banners/messages, and endpoint visual configuration such as wallpaper. ATT&CK provides no official detection text, but the related detection strategy DET0082 points to defacement through UI or messaging modifications. Investigations should correlate defacement artifacts with preceding authentication, administrative access, file modification, configuration change, and remote management activity. Relationship context links this technique to ransomware and wiper software families as well as named groups, so analysts should avoid treating it as isolated until integrity and lateral movement checks are complete.

Likely telemetry

  • File integrity and change records for internal website content and web roots
  • Web server access and administrative logs for internal sites
  • Endpoint logs showing wallpaper, shell, desktop, or user-interface configuration changes
  • System configuration and audit logs for server login banners or messages
  • Authentication and privilege-use logs around systems where defacement appeared

Detection direction

  • Baseline approved internal website content, login messages, and endpoint visual settings, then alert on unauthorized modification.
  • Tune detections to distinguish legitimate IT communications, branding updates, maintenance banners, and helpdesk-driven wallpaper changes from unexpected or broad changes.
  • Correlate defacement with recent administrative logons, privilege escalation, remote execution, file writes, and configuration changes rather than relying only on the visible artifact.
  • Prioritize alerts where defacement appears across multiple systems, critical servers, or virtualization platforms, as this may indicate broader access.
  • Use DET0082 as the relationship-backed detection strategy reference, but validate locally because the ATT&CK object does not provide official detection logic.

Mitigation priorities

  • Ensure Data Backup mitigation M1053 is operational for end-user systems and critical servers, including hardened, isolated backups protected from compromise during active incidents.
  • Maintain recovery procedures for internal web content, server configurations, and endpoint settings so defacement can be reversed without destroying forensic evidence.
  • Restrict and audit administrative paths capable of modifying internal websites, login messages, desktop settings, and ESXi/Linux/macOS/Windows system configurations.
  • Prepare incident communications playbooks for user-facing intimidation or misleading messages so employees receive trusted guidance quickly.
  • After containment, validate system integrity and investigate preceding intrusion activity before declaring the event resolved.
Additional notes and limits

The most important decision point is whether the defacement is the final visible impact or a signal of deeper compromise. Relationship context includes Lazarus Group, Gamaredon Group, BlackByte, Remcos, Diavol, Meteor, BlackCat, Black Basta, INC Ransomware, ROADSWEEP, ShrinkLocker, RansomHub, Qilin, and SameCoin, but these are ATT&CK associations and should not be treated as attribution without local evidence.

Official ATT&CK detection guidance is not provided for this object. The recommendations above are derived from the supplied description, platforms, mitigation relationship to Data Backup, parent Defacement relationship, and DET0082 detection-strategy relationship. Local architecture, logging coverage, business-approved UI changes, and incident evidence are required to determine actual exposure or detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Internal Defacement

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper.[1][2] Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.[3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1491DefacementThis object subtechnique of Defacement.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

GroupEnterprise

G1043: BlackByte

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations initially used a common encryption key allowing for the development of a universal decryptor, but subsequent versions such as BlackByte 2.0 Ransomware use more robust encryption mechanisms. BlackByte is notable for operations targeting critical infrastructure entities among other targets across North America.[1][2][3][4][5]

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

ToolEnterprise

S0332: Remcos

Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.[1][2]

Windows
MalwareEnterprise

S1178: ShrinkLocker

ShrinkLocker is a VBS-based malicious script that leverages the legitimate Bitlocker application to encrypt files on victim systems for ransom. ShrinkLocker functions by using Bitlocker to encrypt files, then renames impacted drives to the adversary’s contact email address to facilitate communication for the ransom payment.[1][2]

Windows
MalwareEnterprise

S1070: Black Basta

Black Basta is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since at least April 2022; there are variants that target Windows and VMWare ESXi servers. Black Basta operations have included the double extortion technique where in addition to demanding ransom for decrypting the files of targeted organizations the cyber actors also threaten to post sensitive information to a leak site if the ransom is not paid. Black Basta affiliates have targeted multiple high-value organizations, with the largest number of victims based in the U.S. Based on similarities in TTPs, leak sites, payment sites, and negotiation tactics, security researchers assess the Black Basta RaaS operators could include current or former members of the Conti group.[1][2][3][4][5][6]

WindowsESXi
MalwareEnterprise

S0659: Diavol

Diavol is a ransomware variant first observed in June 2021 that is capable of prioritizing file types to encrypt based on a pre-configured list of extensions defined by the attacker. The Diavol Ransomware-as-a Service (RaaS) program is managed by Wizard Spider and it has been observed being deployed by Bazar.[1][2][3][4]

Windows
MalwareEnterprise

S9030: SameCoin

SameCoin is a multi-platform wiper with Windows and Android versions that has been used by WIRTE to target entities in the Middle East including in Israel.[1]

WindowsAndroid
MalwareEnterprise

S0688: Meteor

Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.[1]

Windows
MalwareEnterprise

S1212: RansomHub

RansomHub is a ransomware-as-a-service (RaaS) offering with Windows, ESXi, Linux, and FreeBSD versions that has been in use since at least 2024 to target organizations in multiple sectors globally. RansomHub operators may have purchased and rebranded resources from Knight (formerly Cyclops) Ransomware which shares infrastructure, feature, and code overlaps with RansomHub.[1][2]

LinuxWindows
MalwareEnterprise

S1068: BlackCat

BlackCat is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First observed November 2021, BlackCat has been used to target multiple sectors and organizations in various countries and regions in Africa, the Americas, Asia, Australia, and Europe.[1][2][3]

LinuxWindows
MalwareEnterprise

S1242: Qilin

Qilin is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at least 2022. It includes variants written in Go and Rust capable of targeting Windows, Linux, and VMware ESXi environments. Qilin shares functionality overlaps with Black Basta, REvil, and BlackCat ransomware. Qilin affiliates have targeted multiple entities worldwide with the majority of victims in the US, France, Canada, and the UK, primarily in the manufacturing, technology, financial services, and healthcare sectors.[1][2][3][4][5]

ESXiWindowsLinux
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
ed6dfb377e5788b4...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundleed6dfb377e57…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  2. [2]
    Varonis

    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

    Open source URL
  3. [3]
    Novetta Blockbuster Destructive Malware

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.

    Open source URL
  4. [4]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  5. [5]
    CERT-EE Gamaredon January 2021

    CERT-EE. (2021, January 27). Gamaredon Infection: From Dropper to Entry. Retrieved February 17, 2022.

    Open source URL
  6. [6]
    Kaspersky ShrinkLocker 2024

    Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.

    Open source URL
  7. [7]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  8. [8]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  9. [9]
    BlackBerry Black Basta May 2022

    Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023.

    Open source URL
  10. [10]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  11. [11]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  12. [12]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  13. [13]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  14. [14]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  15. [15]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  16. [16]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  17. [17]
    Fortinet Diavol July 2021

    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.

    Open source URL
  18. [18]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  19. [19]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  20. [20]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  21. [21]
    Ready.gov IT DRP

    Ready.gov. (n.d.). IT Disaster Recovery Plan. Retrieved March 15, 2019.

    Open source URL
  22. [22]
    Check Point Meteor Aug 2021

    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

    Open source URL
  23. [23]
    CISA RansomHub AUG 2024

    CISA et al. (2024, August 29). #StopRansomware: RansomHub Ransomware. Retrieved March 17, 2025.

    Open source URL
  24. [24]
    Microsoft BlackCat Jun 2022

    Microsoft Defender Threat Intelligence. (2022, June 13). The many lives of BlackCat ransomware. Retrieved December 20, 2022.

    Open source URL
  25. [25]
    Sophos BlackCat Jul 2022

    Brandt, Andrew. (2022, July 14). BlackCat ransomware attacks not merely a byproduct of bad luck. Retrieved December 20, 2022.

    Open source URL
  26. [26]
    Sophos Qilin MSP APR 2025

    Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.

    Open source URL
  27. [27]
    Trend Micro Agenda Ransomware OCT 2025

    Trend Micro. (2025, October 23). Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques. Retrieved March 26, 2026.

    Open source URL
  28. [28]
    Cisco Talos Qilin Ransomware OCT 2025

    Takeda, T. et al. (2025, October 26). Uncovering Qilin attack methods exposed through multiple cases. Retrieved March 26, 2026.

    Open source URL
  29. [29]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  30. [30]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  31. [31]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  32. [32]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  33. [33]
    Novetta Blockbuster Destructive Malware

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.

    Open source URL
  34. [34]
    Novetta Blockbuster Destructive Malware

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.

    Open source URL
  35. [35]
    Varonis

    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

    Open source URL
  36. [36]
    Varonis

    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

    Open source URL
  37. [37]
    mitre-attackT1491.001
    Open source URL
  38. [38]
    mitre-attackT1491.001
    Open source URL
  39. [39]
    mitre-attackT1491.001
    Open source URL
  40. [40]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  41. [41]
    CERT-EE Gamaredon January 2021

    CERT-EE. (2021, January 27). Gamaredon Infection: From Dropper to Entry. Retrieved February 17, 2022.

    Open source URL
  42. [42]
    Kaspersky ShrinkLocker 2024

    Cristian Souza, Eduardo Ovalle, Ashley Muñoz, & Christopher Zachor. (2024, May 23). ShrinkLocker: Turning BitLocker into ransomware. Retrieved December 7, 2024.

    Open source URL
  43. [43]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  44. [44]
    Avertium Black Basta June 2022

    Avertium. (2022, June 1). AN IN-DEPTH LOOK AT BLACK BASTA RANSOMWARE. Retrieved March 7, 2023.

    Open source URL
  45. [45]
    BlackBerry Black Basta May 2022

    Ballmer, D. (2022, May 6). Black Basta: Rebrand of Conti or Something New?. Retrieved March 7, 2023.

    Open source URL
  46. [46]
    Check Point Black Basta October 2022

    Check Point. (2022, October 20). BLACK BASTA AND THE UNNOTICED DELIVERY. Retrieved March 8, 2023.

    Open source URL
  47. [47]
    Cyble Black Basta May 2022

    Cyble. (2022, May 6). New ransomware variant targeting high-value organizations. Retrieved November 17, 2024.

    Open source URL
  48. [48]
    Deep Instinct Black Basta August 2022

    Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  49. [49]
    Minerva Labs Black Basta May 2022

    Zargarov, N. (2022, May 2). New Black Basta Ransomware Hijacks Windows Fax Service. Retrieved March 7, 2023.

    Open source URL
  50. [50]
    NCC Group Black Basta June 2022

    Inman, R. and Gurney, P. (2022, June 6). Shining the Light on Black Basta. Retrieved March 8, 2023.

    Open source URL
  51. [51]
    Palo Alto Networks Black Basta August 2022

    Elsad, A. (2022, August 25). Threat Assessment: Black Basta Ransomware. Retrieved March 8, 2023.

    Open source URL
  52. [52]
    Trend Micro Black Basta May 2022

    Gonzalez, I., Chavez I., et al. (2022, May 9). Examining the Black Basta Ransomware’s Infection Routine. Retrieved March 7, 2023.

    Open source URL
  53. [53]
    Fortinet Diavol July 2021

    Neeamni, D., Rubinfeld, A.. (2021, July 1). Diavol - A New Ransomware Used By Wizard Spider?. Retrieved November 12, 2021.

    Open source URL
  54. [54]
    Check Point Wirte NOV 2024

    Check Point. (2024, November 12). Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity. Retrieved April 20, 2026.

    Open source URL
  55. [55]
    FBI BlackByte 2022

    US Federal Bureau of Investigation & US Secret Service. (2022, February 11). Indicators of Compromise Associated with BlackByte Ransomware. Retrieved December 16, 2024.

    Open source URL
  56. [56]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  57. [57]
    Ready.gov IT DRP

    Ready.gov. (n.d.). IT Disaster Recovery Plan. Retrieved March 15, 2019.

    Open source URL
  58. [58]
    Check Point Meteor Aug 2021

    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

    Open source URL
  59. [59]
    Novetta Blockbuster Destructive Malware

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.

    Open source URL
  60. [60]
    Novetta Blockbuster Destructive Malware

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.

    Open source URL
  61. [61]
    CISA RansomHub AUG 2024

    CISA et al. (2024, August 29). #StopRansomware: RansomHub Ransomware. Retrieved March 17, 2025.

    Open source URL
  62. [62]
    Microsoft BlackCat Jun 2022

    Microsoft Defender Threat Intelligence. (2022, June 13). The many lives of BlackCat ransomware. Retrieved December 20, 2022.

    Open source URL
  63. [63]
    Sophos BlackCat Jul 2022

    Brandt, Andrew. (2022, July 14). BlackCat ransomware attacks not merely a byproduct of bad luck. Retrieved December 20, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.