Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
MalwareTrickBot | TrickBot can disable Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareEKANS | EKANS stops processes related to security and management software. |
| T1685 Disable or Modify Tools |
MalwareJumbledPath | JumbledPath can impair logging on all devices used along its connection path to compromised hosts. |
| T1685 Disable or Modify Tools |
MalwareStuxnet | Stuxnet reduces the integrity level of objects to allow write actions. |
| T1685 Disable or Modify Tools |
MalwareRobbinHood | RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process. |
| T1685 Disable or Modify Tools |
MalwareStrongPity | StrongPity can add directories used by the malware to the Windows Defender exclusions list to prevent detection. |
| T1685 Disable or Modify Tools |
MalwareBrave Prince | Brave Prince terminates antimalware processes. |
| T1685 Disable or Modify Tools |
MalwareMedusa Ransomware | Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts. |
| T1685 Disable or Modify Tools |
MalwaremacOS.OSAMiner | macOS.OSAMiner has searched for the Activity Monitor process in the System Events process list and kills the process if running. macOS.OSAMiner also searches the operating system's `install.log` for apps matching its hardcoded list, killing all matching process names. |
| T1685 Disable or Modify Tools |
MalwareSslMM | SslMM identifies and kills anti-malware processes. |
| T1685 Disable or Modify Tools |
MalwareBOLDMOVE | BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging. |
| T1685 Disable or Modify Tools |
MalwareWoody RAT | Woody RAT has suppressed all error reporting by calling `SetErrorMode` with 0x8007 as a parameter. |
| T1685 Disable or Modify Tools |
MalwareShrinkLocker | ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems. |
| T1685 Disable or Modify Tools |
MalwareHildegard | Hildegard has modified DNS resolvers to evade DNS monitoring tools. |
| T1685 Disable or Modify Tools |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive. |
| T1685 Disable or Modify Tools |
MalwareSkidmap | Skidmap has the ability to set SELinux to permissive mode. |
| T1685 Disable or Modify Tools |
MalwareRaspberry Robin | Raspberry Robin can add an exception to Microsoft Defender that excludes the entire main drive from anti-malware scanning to evade detection. |
| T1685 Disable or Modify Tools |
MalwareDiavol | Diavol can attempt to stop security software. |
| T1685 Disable or Modify Tools |
MalwareDarkComet | DarkComet can disable Security Center functions like anti-virus. |
| T1685 Disable or Modify Tools |
MalwareHUI Loader | HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions. |
| T1685 Disable or Modify Tools |
MalwareRagnar Locker | Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products. |
| T1685 Disable or Modify Tools |
MalwareAvaddon | Avaddon looks for and attempts to stop anti-malware solutions. |
| T1685 Disable or Modify Tools |
MalwareConficker | Conficker terminates various services related to system security and Windows. |
| T1685 Disable or Modify Tools |
MalwareLockerGoga | LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus. |
| T1685 Disable or Modify Tools |
MalwareRunningRAT | RunningRAT kills antimalware running process. |
| T1685 Disable or Modify Tools |
MalwareBabuk | Babuk can stop anti-virus services on a compromised host. |
| T1685 Disable or Modify Tools |
MalwareMultiLayer Wiper | MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies. |
| T1685 Disable or Modify Tools |
MalwareLumma Stealer | Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called. |
| T1685 Disable or Modify Tools |
MalwarePureCrypter | PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans. |
| T1685 Disable or Modify Tools |
MalwareDarkGate | DarkGate will terminate processes associated with several security software products if identified during execution. |
| T1685 Disable or Modify Tools |
MalwareNanHaiShu | NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity. |
| T1685 Disable or Modify Tools |
MalwareLockBit 3.0 | LockBit 3.0 can disable security tools to evade detection including Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareThiefQuest | ThiefQuest uses the function |
| T1685 Disable or Modify Tools |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
| T1685 Disable or Modify Tools |
MalwareBundlore | Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the |
| T1685 Disable or Modify Tools |
MalwareMetamorfo | Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching. |
| T1685 Disable or Modify Tools |
MalwareRedLine Stealer | RedLine Stealer can disable security software and update services. |
| T1685 Disable or Modify Tools |
MalwareMegaCortex | MegaCortex was used to kill endpoint security processes. |
| T1685 Disable or Modify Tools |
MalwareBlackByte Ransomware | BlackByte Ransomware adds .JS and .EXE extensions to the Microsoft Defender exclusion list. BlackByte Ransomware terminates and removes the Raccine anti-ransomware utility. |
| T1685 Disable or Modify Tools |
MalwareGrandoreiro | Grandoreiro can hook APIs, kill processes, break file system paths, and change ACLs to prevent security tools from running. |
| T1685 Disable or Modify Tools |
MalwareBazar | Bazar has manually loaded ntdll from disk in order to identity and remove API hooks set by security products. |
| T1685 Disable or Modify Tools |
MalwareXLoader | XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareRyuk | Ryuk has stopped services related to anti-virus. |
| T1685 Disable or Modify Tools |
MalwareHermeticWiper | HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps. |
| T1685 Disable or Modify Tools |
MalwarePysa | Pysa has the capability to stop antivirus services and disable Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareLockBit 2.0 | LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareCobalt Strike | Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox. |
| T1685 Disable or Modify Tools |
MalwareSUNBURST | SUNBURST attempted to disable software security services following checks against a FNV-1a + XOR hashed hardcoded blocklist. |
| T1685 Disable or Modify Tools |
MalwareUnknown Logger | Unknown Logger has functionality to disable security tools, including Kaspersky, BitDefender, and MalwareBytes. |
| T1685 Disable or Modify Tools |
MalwareREvil | REvil can connect to and disable the Symantec server on the victim's network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.