T1685 Disable or Modify Tools — ATT&CK Technique
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments. In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion). More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.
Detection coverage (50)
- Potential Ke3chang/TidePool Malware Activity high
- Diamond Sleet APT Scheduled Task Creation - Registry high
- Disable Or Stop Services medium
- RedSun - TieringEngineService.exe Detected as EICAR Test File critical
- RedSun - Named Pipe Created critical
- Terminate Linux Process Via Kill medium
- WDAC Policy File Creation In CodeIntegrity Folder medium
- WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze medium
- Bitbucket Global Secret Scanning Rule Deleted medium
- Bitbucket Project Secret Scanning Allowlist Added low
- Bitbucket Audit Log Configuration Updated medium
- Bitbucket Secret Scanning Exempt Repository Added high
- Bitbucket Global SSH Settings Changed medium
- Github Push Protection Bypass Detected low
- Bitbucket Secret Scanning Rule Deleted low
- Github Secret Scanning Feature Disabled high
- Github Push Protection Disabled high
- AWS GuardDuty Detector Deleted Or Updated high
- AWS GuardDuty Important Change high
- AWS SecurityHub Findings Evasion high
- Azure Kubernetes Events Deleted medium
- FortiGate - New Firewall Policy Added medium
- Google Cloud Firewall Modified or Deleted medium
- Service StartupType Change Via PowerShell Set-Service medium
- Auditing Configuration Changes on Linux Host high
- Logging Configuration Changes on Linux Host high
- Okta User Session Start Via An Anonymising Proxy Service high
- Suspicious Uninstall of Windows Defender Feature via PowerShell high
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux high
- ESXi Syslog Configuration Change Via ESXCLI medium
- PUA - CleanWipe Execution high
- Disable Security Tools medium
- Cisco Dot1x Disabled medium
- Cisco Disabling Logging high
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE medium
- Add SafeBoot Keys Via Reg Utility high
- SafeBoot Registry Key Deleted Via Reg.EXE high
- Disabling Windows Defender WMI Autologger Session via Reg.exe high
- Reg Add Suspicious Paths high
- Write Protect For Storage Disabled medium
- Service Registry Key Deleted Via Reg.EXE high
- Disabled Volume Snapshots high
- ASLR Disabled Via Sysctl or Direct Syscall - Linux high
- Security Service Disabled Via Reg.EXE high
- Suspicious Windows Defender Registry Key Tampering Via Reg.EXE high
- FortiGate - Firewall Address Object Added medium
- Microsoft Malware Protection Engine Crash high
- Microsoft Malware Protection Engine Crash - WER high
- Weak Encryption Enabled and Kerberoast high
- Windows Filtering Platform Blocked Connection From EDR Agent Binary high
Malware using this technique
- KOCTOPUS
- SplatCloak
- macOS.OSAMiner
- MegaCortex
- JPIN
- Babuk
- Raspberry Robin
- HermeticWiper
- Ragnar Locker
- WhisperGate
- Netwalker
- WarzoneRAT
- XLoader
- RedLine Stealer
- Gold Dragon
- RunningRAT
- DarkGate
- QakBot
- LazyWiper
- TinyZBot
- LockBit 2.0
- NanHaiShu
- PureCrypter
- Skidmap
- JumbledPath
- Shai-Hulud
- SILENTTRINITY
- Unknown Logger
- Diavol
- Brave Prince
- Avaddon
- LockBit 3.0
- NanoCore
- Pysa
- ThiefQuest
- SUNBURST
- Meteor
- Imminent Monitor
- REvil
- Goopy
- Proton
- Bundlore
- Lumma Stealer
- LockerGoga
- Mango
- Brute Ratel C4
- Hildegard
- Egregor
- RobbinHood
- Grandoreiro
Threat actors using this technique
- Scattered Spider
- Kimsuky
- Gorgon Group
- FIN6
- MirrorFace
- Agrius
- APT5
- TA2541
- BlackByte
- Evil Corp
- Contagious Interview
- APT38
- Saint Bear
- Putter Panda
- Conti
- APT41
- BRONZE BUTLER
- Turla
- Lazarus Group
- MuddyWater
- Gamaredon Group
- INC Ransom
- UNC3886
- Aquatic Panda
- Velvet Ant
- TeamTNT
- Akira
- Medusa Group
- TA505
- Rocke
- APT35
- Play Ransomware