Cross-source coverage

T1685 / ATT&CK

Disable or Modify Tools

359 rules across 2 sources.

2 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion).

More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.

Platforms
Containers · ESXi · IaaS · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SystemWinEventLog:Sysmonauditd:SYSCALLauditd:CONFIG_CHANGEmacos:unifiedlogAWS:CloudTrailkubernetes:auditnetworkdevice:confignetworkdevice:syslogesxi:shellesxi:hostd

How MITRE says to detect it DET0497

Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.

Windows Analytic 1369

Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.

  • WinEventLog:System EventCode=7045
  • WinEventLog:Sysmon EventCode=5
  • WinEventLog:Sysmon EventCode=13, 14

Linux Analytic 1370

Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.

  • auditd:SYSCALL execve: systemctl stop, service stop, or kill -9 on security daemons (e.g., falcon-sensor, auditd)
  • auditd:CONFIG_CHANGE delete: Modification of systemd unit files or config for security agents

macOS Analytic 1371

Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.

  • macos:unifiedlog Execution of launchctl unload, kill, or removal of security agent daemons
  • macos:unifiedlog Modification of system configuration profiles affecting security tools

IaaS Analytic 1372

Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events

  • AWS:CloudTrail Delete* / Stop*: DeleteAlarms, StopLogging, or DisableMonitoring API calls

Containers Analytic 1373

Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.

  • kubernetes:audit kubectl delete or patch of security pods/admission controllers

Network Devices Analytic 1374

Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.

  • networkdevice:config write: Startup configuration changes disabling security checks
  • networkdevice:syslog no logging host, no aaa new-model, no snmp-server, commit

ESXi Analytic 2044

Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity.

  • esxi:shell esxcli system syslog config set/reload, services.sh restart/stop
  • esxi:hostd service state change

Sub-techniques with coverage

Counted in the 359 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

200 rules
Detection Severity Format
NotPetya Ransomware Activity Critical Sigma
RedSun - Named Pipe Created Critical Sigma
RedSun - TieringEngineService.exe Detected as EICAR Test File Critical Sigma
Add SafeBoot Keys Via Reg Utility High Sigma
AMSI Bypass Pattern Assembly GetType High Sigma
AMSI Disabled via Registry Modification High Sigma
Antivirus Filter Driver Disallowed On Dev Drive - Registry High Sigma
ASLR Disabled Via Sysctl or Direct Syscall - Linux High Sigma
Auditing Configuration Changes on Linux Host High Sigma
Audit Policy Tampering Via Auditpol High Sigma

+ 190 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

159 rules
Detection Severity Format
Add or Set Windows Defender Exclusion Undefined SPL
ASL AWS Defense Evasion Delete Cloudtrail Undefined SPL
ASL AWS Defense Evasion Delete CloudWatch Log Group Undefined SPL
ASL AWS Defense Evasion Impair Security Services Undefined SPL
ASL AWS Defense Evasion PutBucketLifecycle Undefined SPL
ASL AWS Defense Evasion Stop Logging Cloudtrail Undefined SPL
ASL AWS Defense Evasion Update Cloudtrail Undefined SPL
AWS Bedrock Delete GuardRails Undefined SPL
AWS Bedrock Delete Model Invocation Logging Configuration Undefined SPL
AWS Defense Evasion Delete Cloudtrail Undefined SPL

+ 149 more from splunk/security_content → showing the 10 highest-severity

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.