Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1565.001

T1565.001Stored Data Manipulation

T1565.001 — Stored Data Manipulation is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 15 detection use cases covering it and 11 threat-intel articles citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
11Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Windows WBAdmin File Recovery From Backup ESCU actions · hunting P [LLM] Ruflo AgentDB memory poisoning via MCP pattern-store write Bespoke actions · hunting SΣPDD [LLM] NodeBB federation actor spoofing — new peer POSTing to ActivityPub inbox (CVE-2026-58593 / vote inflation) Bespoke exploit · hunting SP [LLM] Gitea PR-update endpoint enumeration across multiple repositories (CVE-2026-58443) Bespoke actions · hunting SP [LLM] Vitest Browser Mode node.exe writes/deletes PNG or trace archive outside project into system paths Bespoke actions · alerting DSΣPDDCS [LLM] n8n-MCP destructive workflow version backup deletion (delete/prune/truncate) — CVE-2026-54052 impact Bespoke actions · alerting SΣP [LLM] 9router database overwrite via POST /api/settings/database (CVE-2026-55500) Bespoke actions · alerting SΣP [LLM] 9router export-then-import chain from same source (CVE-2026-55500 takeover) Bespoke actions · alerting SP [LLM] Unauthenticated 9router provider CRUD mutation (rogue-provider / key-swap / DoS) Bespoke actions · alerting SΣP [LLM] CVE-2026-50027 unauthenticated write to mcp-memory-service /api/documents/upload Bespoke install · hunting SΣP [LLM] CVE-2026-50027 unauthenticated destructive delete via /api/documents/remove-by-tags Bespoke actions · alerting SΣP [LLM] CVE-2026-50027 full exploit chain: probe, write, bulk-read, delete from one source in 15m Bespoke actions · alerting SP [LLM] Foreign / non-Vertex principal accessing Vertex AI staging-bucket objects Bespoke actions · hunting ΣPDD [LLM] AI coding agent bulk-deleting JUnit test files after jqwik resolution Bespoke actions · alerting DSPDDCS [LLM] FTP client / Hive (commons-net) overwrites Unix auth files via path-traversal LIST (CVE-2018-1315) Bespoke actions · alerting DSΣPCS

Articles citing this technique (11)