Cross-source coverage
T1089 / ATT&CK
Disabling Security Tools
ATT&CK has retired this technique. Rules still tag it; the current id is T1685 Disable or Modify Tools.
7 rules · 6 families across 1 source.
3 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may disable security tools to avoid possible detection of their tools and activities. This can take the form of killing security software or event logging processes, deleting Registry keys so that tools do not start at run time, or other methods to interfere with security scanning or event reporting.
- Tactics
- Stealth
- Platforms
- Linux · macOS · Windows
- Telemetry
- —