MITRE ATT&CK Technique
T1565.001Stored Data Manipulation
- First Reported
- Sep 24, 2026
- Latest Reported
- Sep 24, 2026
Official Description
Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.(Citation: FireEye APT38 Oct 2018)(Citation: DOJ Lazarus Sony 2018) By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making.
Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The type of modification and the impact it will have depends on the type of data as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.
Stored data could include a variety of file formats, such as Office files, databases, stored emails, and custom file formats. The type of modification and the impact it will have depends on the type of data as well as the goals and objectives of the adversary. For complex systems, an adversary would likely need special expertise and possibly access to specialized software related to the system that would typically be gained through a prolonged information gathering campaign in order to have the desired impact.
- Tactics
- Impact
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1565 · Data Manipulation
- MITRE Version
- 1.1
- Last Modified
- Nov 13, 2025
Reported Context (1)
- Researchers overwrote an agent response in Kiro-CLI’s locally stored SQLite conversation history with an UPDATE statement; the harness accepted the altered record. Researchers Show How Tampered Conversation Histories Can Hijack AI Coding Agents
MITRE ATT&CK (2)
Vendors (4)
Products (13)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.