Real-world descriptions of how a group, tool or campaign used a technique.
87 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
MalwareREvil | REvil can connect to and disable the Symantec server on the victim's network. |
| T1685 Disable or Modify Tools |
MalwareNanoCore | NanoCore can modify the victim's anti-virus. |
| T1685 Disable or Modify Tools |
MalwareGold Dragon | Gold Dragon terminates anti-malware processes if they’re found running on the system. |
| T1685 Disable or Modify Tools |
MalwareCarberp | Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed. |
| T1685 Disable or Modify Tools |
MalwareTinyZBot | TinyZBot can disable Avira anti-virus. |
| T1685 Disable or Modify Tools |
MalwareProton | Proton kills security tools like Wireshark that are running. |
| T1685 Disable or Modify Tools |
MalwareMango | Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process. |
| T1685 Disable or Modify Tools |
MalwarePHASEJAM | PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file. |
| T1685 Disable or Modify Tools |
MalwareClop | Clop can uninstall or disable security products. |
| T1685 Disable or Modify Tools |
MalwareEgregor | Egregor has disabled Windows Defender to evade protections. |
| T1685 Disable or Modify Tools |
MalwareStealBit | StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`. |
| T1685 Disable or Modify Tools |
MalwareZxShell | ZxShell can kill AV products' processes. |
| T1685 Disable or Modify Tools |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection. |
| T1685 Disable or Modify Tools |
MalwareEbury | Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules. |
| T1685 Disable or Modify Tools |
MalwareMeteor | Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareZIPLINE | ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process. |
| T1685 Disable or Modify Tools |
MalwareMaze | Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services. |
| T1685 Disable or Modify Tools |
MalwareChChes | ChChes can alter the victim's proxy configuration. |
| T1685 Disable or Modify Tools |
MalwareShai-Hulud | Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`. |
| T1685 Disable or Modify Tools |
MalwareJPIN | JPIN can lower security settings by changing Registry keys. |
| T1685 Disable or Modify Tools |
MalwareKOCTOPUS | KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
| T1685 Disable or Modify Tools |
MalwareLazyWiper | LazyWiper can disable Microsoft Windows Defender Real-Time Monitoring with the `Set-MpPreference` cmdlet. |
| T1685 Disable or Modify Tools |
MalwareAgent Tesla | Agent Tesla has the capability to kill any running analysis processes and AV software. |
| T1685 Disable or Modify Tools |
MalwarePOWERSTATS | POWERSTATS can disable Microsoft Office Protected View by changing Registry keys. |
| T1685 Disable or Modify Tools |
MalwareDRYHOOK | DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated. |
| T1685 Disable or Modify Tools |
MalwareGoopy | Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings. |
| T1685 Disable or Modify Tools |
MalwareQakBot | QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareSplatCloak | SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky. |
| T1685 Disable or Modify Tools |
MalwareWaterbear | Waterbear can hook the |
| T1685 Disable or Modify Tools |
MalwareH1N1 | H1N1 kills and disables services for Windows Security Center, and Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareWarzoneRAT | WarzoneRAT can disarm Windows Defender during the UAC process to evade detection. |
| T1685 Disable or Modify Tools |
ToolSILENTTRINITY | SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions. |
| T1685 Disable or Modify Tools |
ToolDCRAT | DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection. |
| T1685 Disable or Modify Tools |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI). |
| T1685 Disable or Modify Tools |
ToolImminent Monitor | Imminent Monitor has a feature to disable Windows Task Manager. |
| T1685 Disable or Modify Tools |
ToolDonut | Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.