Cross-source coverage
T1685 / ATT&CK
Disable or Modify Tools
359 rules across 2 sources.
2 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion).
More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.
- Tactics
- Defense Impairment
- Platforms
- Containers · ESXi · IaaS · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SystemWinEventLog:Sysmonauditd:SYSCALLauditd:CONFIG_CHANGEmacos:unifiedlogAWS:CloudTrailkubernetes:auditnetworkdevice:confignetworkdevice:syslogesxi:shellesxi:hostd
How MITRE says to detect it DET0497
Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
Windows Analytic 1369
Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.
WinEventLog:SystemEventCode=7045WinEventLog:SysmonEventCode=5WinEventLog:SysmonEventCode=13, 14
Linux Analytic 1370
Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.
auditd:SYSCALLexecve: systemctl stop, service stop, or kill -9 on security daemons (e.g., falcon-sensor, auditd)auditd:CONFIG_CHANGEdelete: Modification of systemd unit files or config for security agents
macOS Analytic 1371
Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.
macos:unifiedlogExecution of launchctl unload, kill, or removal of security agent daemonsmacos:unifiedlogModification of system configuration profiles affecting security tools
IaaS Analytic 1372
Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events
AWS:CloudTrailDelete* / Stop*: DeleteAlarms, StopLogging, or DisableMonitoring API calls
Containers Analytic 1373
Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.
kubernetes:auditkubectl delete or patch of security pods/admission controllers
Network Devices Analytic 1374
Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.
networkdevice:configwrite: Startup configuration changes disabling security checksnetworkdevice:syslogno logging host, no aaa new-model, no snmp-server, commit
ESXi Analytic 2044
Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity.
esxi:shellesxcli system syslog config set/reload, services.sh restart/stopesxi:hostdservice state change
Sub-techniques with coverage
Counted in the 359 above — a rule tagged a sub-technique covers this technique too.
SigmaHQ/sigma
200 rules| Detection | Severity | Format |
|---|---|---|
| NotPetya Ransomware Activity | Critical | Sigma |
| RedSun - Named Pipe Created | Critical | Sigma |
| RedSun - TieringEngineService.exe Detected as EICAR Test File | Critical | Sigma |
| Add SafeBoot Keys Via Reg Utility | High | Sigma |
| AMSI Bypass Pattern Assembly GetType | High | Sigma |
| AMSI Disabled via Registry Modification | High | Sigma |
| Antivirus Filter Driver Disallowed On Dev Drive - Registry | High | Sigma |
| ASLR Disabled Via Sysctl or Direct Syscall - Linux | High | Sigma |
| Auditing Configuration Changes on Linux Host | High | Sigma |
| Audit Policy Tampering Via Auditpol | High | Sigma |
+ 190 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
159 rules| Detection | Severity | Format |
|---|---|---|
| Add or Set Windows Defender Exclusion | Undefined | SPL |
| ASL AWS Defense Evasion Delete Cloudtrail | Undefined | SPL |
| ASL AWS Defense Evasion Delete CloudWatch Log Group | Undefined | SPL |
| ASL AWS Defense Evasion Impair Security Services | Undefined | SPL |
| ASL AWS Defense Evasion PutBucketLifecycle | Undefined | SPL |
| ASL AWS Defense Evasion Stop Logging Cloudtrail | Undefined | SPL |
| ASL AWS Defense Evasion Update Cloudtrail | Undefined | SPL |
| AWS Bedrock Delete GuardRails | Undefined | SPL |
| AWS Bedrock Delete Model Invocation Logging Configuration | Undefined | SPL |
| AWS Defense Evasion Delete Cloudtrail | Undefined | SPL |
+ 149 more from splunk/security_content → showing the 10 highest-severity