ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
MalwareTrickBot

TrickBot can disable Windows Defender.

T1685
Disable or Modify Tools
MalwareEKANS

EKANS stops processes related to security and management software.

T1685
Disable or Modify Tools
MalwareJumbledPath

JumbledPath can impair logging on all devices used along its connection path to compromised hosts.

T1685
Disable or Modify Tools
MalwareStuxnet

Stuxnet reduces the integrity level of objects to allow write actions.

T1685
Disable or Modify Tools
MalwareRobbinHood

RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process.

T1685
Disable or Modify Tools
MalwareStrongPity

StrongPity can add directories used by the malware to the Windows Defender exclusions list to prevent detection.

T1685
Disable or Modify Tools
MalwareBrave Prince

Brave Prince terminates antimalware processes.

T1685
Disable or Modify Tools
MalwareMedusa Ransomware

Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts.

T1685
Disable or Modify Tools
MalwaremacOS.OSAMiner

macOS.OSAMiner has searched for the Activity Monitor process in the System Events process list and kills the process if running. macOS.OSAMiner also searches the operating system's `install.log` for apps matching its hardcoded list, killing all matching process names.

T1685
Disable or Modify Tools
MalwareSslMM

SslMM identifies and kills anti-malware processes.

T1685
Disable or Modify Tools
MalwareBOLDMOVE

BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging.

T1685
Disable or Modify Tools
MalwareWoody RAT

Woody RAT has suppressed all error reporting by calling `SetErrorMode` with 0x8007 as a parameter.

T1685
Disable or Modify Tools
MalwareShrinkLocker

ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems.

T1685
Disable or Modify Tools
MalwareHildegard

Hildegard has modified DNS resolvers to evade DNS monitoring tools.

T1685
Disable or Modify Tools
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive.

T1685
Disable or Modify Tools
MalwareSkidmap

Skidmap has the ability to set SELinux to permissive mode.

T1685
Disable or Modify Tools
MalwareRaspberry Robin

Raspberry Robin can add an exception to Microsoft Defender that excludes the entire main drive from anti-malware scanning to evade detection.

T1685
Disable or Modify Tools
MalwareDiavol

Diavol can attempt to stop security software.

T1685
Disable or Modify Tools
MalwareDarkComet

DarkComet can disable Security Center functions like anti-virus.

T1685
Disable or Modify Tools
MalwareHUI Loader

HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions.

T1685
Disable or Modify Tools
MalwareRagnar Locker

Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products.

T1685
Disable or Modify Tools
MalwareAvaddon

Avaddon looks for and attempts to stop anti-malware solutions.

T1685
Disable or Modify Tools
MalwareConficker

Conficker terminates various services related to system security and Windows.

T1685
Disable or Modify Tools
MalwareLockerGoga

LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus.

T1685
Disable or Modify Tools
MalwareRunningRAT

RunningRAT kills antimalware running process.

T1685
Disable or Modify Tools
MalwareBabuk

Babuk can stop anti-virus services on a compromised host.

T1685
Disable or Modify Tools
MalwareMultiLayer Wiper

MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies.

T1685
Disable or Modify Tools
MalwareLumma Stealer

Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called.

T1685
Disable or Modify Tools
MalwarePureCrypter

PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans.

T1685
Disable or Modify Tools
MalwareDarkGate

DarkGate will terminate processes associated with several security software products if identified during execution.

T1685
Disable or Modify Tools
MalwareNanHaiShu

NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity.

T1685
Disable or Modify Tools
MalwareLockBit 3.0

LockBit 3.0 can disable security tools to evade detection including Windows Defender.

T1685
Disable or Modify Tools
MalwareThiefQuest

ThiefQuest uses the function kill_unwanted to obtain a list of running processes and kills each process matching a list of security related processes.

T1685
Disable or Modify Tools
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

T1685
Disable or Modify Tools
MalwareBundlore

Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the pkill cfprefsd command to prevent users from inspecting processes.

T1685
Disable or Modify Tools
MalwareMetamorfo

Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching.

T1685
Disable or Modify Tools
MalwareRedLine Stealer

RedLine Stealer can disable security software and update services.

T1685
Disable or Modify Tools
MalwareMegaCortex

MegaCortex was used to kill endpoint security processes.

T1685
Disable or Modify Tools
MalwareBlackByte Ransomware

BlackByte Ransomware adds .JS and .EXE extensions to the Microsoft Defender exclusion list. BlackByte Ransomware terminates and removes the Raccine anti-ransomware utility.

T1685
Disable or Modify Tools
MalwareGrandoreiro

Grandoreiro can hook APIs, kill processes, break file system paths, and change ACLs to prevent security tools from running.

T1685
Disable or Modify Tools
MalwareBazar

Bazar has manually loaded ntdll from disk in order to identity and remove API hooks set by security products.

T1685
Disable or Modify Tools
MalwareXLoader

XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list.

T1685
Disable or Modify Tools
MalwareRyuk

Ryuk has stopped services related to anti-virus.

T1685
Disable or Modify Tools
MalwareHermeticWiper

HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps.

T1685
Disable or Modify Tools
MalwarePysa

Pysa has the capability to stop antivirus services and disable Windows Defender.

T1685
Disable or Modify Tools
MalwareLockBit 2.0

LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender.

T1685
Disable or Modify Tools
MalwareCobalt Strike

Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox.

T1685
Disable or Modify Tools
MalwareSUNBURST

SUNBURST attempted to disable software security services following checks against a FNV-1a + XOR hashed hardcoded blocklist.

T1685
Disable or Modify Tools
MalwareUnknown Logger

Unknown Logger has functionality to disable security tools, including Kaspersky, BitDefender, and MalwareBytes.

T1685
Disable or Modify Tools
MalwareREvil

REvil can connect to and disable the Symantec server on the victim's network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.