ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1685×

87 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
MalwareREvil

REvil can connect to and disable the Symantec server on the victim's network.

T1685
Disable or Modify Tools
MalwareNanoCore

NanoCore can modify the victim's anti-virus.

T1685
Disable or Modify Tools
MalwareGold Dragon

Gold Dragon terminates anti-malware processes if they’re found running on the system.

T1685
Disable or Modify Tools
MalwareCarberp

Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed.

T1685
Disable or Modify Tools
MalwareTinyZBot

TinyZBot can disable Avira anti-virus.

T1685
Disable or Modify Tools
MalwareProton

Proton kills security tools like Wireshark that are running.

T1685
Disable or Modify Tools
MalwareMango

Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process.

T1685
Disable or Modify Tools
MalwarePHASEJAM

PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file.

T1685
Disable or Modify Tools
MalwareClop

Clop can uninstall or disable security products.

T1685
Disable or Modify Tools
MalwareEgregor

Egregor has disabled Windows Defender to evade protections.

T1685
Disable or Modify Tools
MalwareStealBit

StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`.

T1685
Disable or Modify Tools
MalwareZxShell

ZxShell can kill AV products' processes.

T1685
Disable or Modify Tools
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection.

T1685
Disable or Modify Tools
MalwareEbury

Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules.

T1685
Disable or Modify Tools
MalwareMeteor

Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list.

T1685
Disable or Modify Tools
MalwareZIPLINE

ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process.

T1685
Disable or Modify Tools
MalwareMaze

Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services.

T1685
Disable or Modify Tools
MalwareChChes

ChChes can alter the victim's proxy configuration.

T1685
Disable or Modify Tools
MalwareShai-Hulud

Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`.

T1685
Disable or Modify Tools
MalwareJPIN

JPIN can lower security settings by changing Registry keys.

T1685
Disable or Modify Tools
MalwareKOCTOPUS

KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials.

T1685
Disable or Modify Tools
MalwareQilin

Qilin can terminate antivirus-related processes and services.

T1685
Disable or Modify Tools
MalwareLazyWiper

LazyWiper can disable Microsoft Windows Defender Real-Time Monitoring with the `Set-MpPreference` cmdlet.

T1685
Disable or Modify Tools
MalwareAgent Tesla

Agent Tesla has the capability to kill any running analysis processes and AV software.

T1685
Disable or Modify Tools
MalwarePOWERSTATS

POWERSTATS can disable Microsoft Office Protected View by changing Registry keys.

T1685
Disable or Modify Tools
MalwareDRYHOOK

DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated.

T1685
Disable or Modify Tools
MalwareGoopy

Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings.

T1685
Disable or Modify Tools
MalwareQakBot

QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list.

T1685
Disable or Modify Tools
MalwareSplatCloak

SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky.

T1685
Disable or Modify Tools
MalwareWaterbear

Waterbear can hook the ZwOpenProcess and GetExtendedTcpTable APIs called by the process of a security product to hide PIDs and TCP records from detection.

T1685
Disable or Modify Tools
MalwareH1N1

H1N1 kills and disables services for Windows Security Center, and Windows Defender.

T1685
Disable or Modify Tools
MalwareWarzoneRAT

WarzoneRAT can disarm Windows Defender during the UAC process to evade detection.

T1685
Disable or Modify Tools
ToolSILENTTRINITY

SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions.

T1685
Disable or Modify Tools
ToolDCRAT

DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection.

T1685
Disable or Modify Tools
ToolBrute Ratel C4

Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI).

T1685
Disable or Modify Tools
ToolImminent Monitor

Imminent Monitor has a feature to disable Windows Task Manager.

T1685
Disable or Modify Tools
ToolDonut

Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.