Cross-source coverage

T1089 / ATT&CK

Disabling Security Tools

ATT&CK has retired this technique. Rules still tag it; the current id is T1685 Disable or Modify Tools.

7 rules · 6 families across 1 source.

3 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may disable security tools to avoid possible detection of their tools and activities. This can take the form of killing security software or event logging processes, deleting Registry keys so that tools do not start at run time, or other methods to interfere with security scanning or event reporting.

Tactics
Stealth
Platforms
Linux · macOS · Windows
Telemetry

socfortress/Wazuh-Rules

7 rules · 6 families
Detection Severity Format
Sysmon - Event 1: Process creation · Disabling Security Tools (T1089) 2 variants High Wazuh XML
Sysmon - Event 12: RegistryEvent (Object create and delete) by · Disabling Security Tools (T1089) Low Wazuh XML
Sysmon - Event 13: RegistryEvent (Value Set) by · Disabling Security Tools (T1089) Low Wazuh XML
Sysmon - Event 14: RegistryEvent (Key and Value Rename) by · Disabling Security Tools (T1089) Low Wazuh XML
Sysmon - Event 15: FileCreateStreamHash by · Drive-by Compromise (T1089) Low Wazuh XML
Sysmon - Event 1: Process creation · Disabling Security Tools (T1089) 2 variants Low Wazuh XML
Sysmon - Event 3: Network connection by · Disabling Security Tools (T1089) Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.