ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
GroupAquatic Panda

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.

T1685
Disable or Modify Tools
GroupSaint Bear

Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality.

T1685
Disable or Modify Tools
GroupTurla

Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products.

T1685
Disable or Modify Tools
GroupTA505

TA505 has used malware to disable Windows Defender.

T1685
Disable or Modify Tools
GroupMirrorFace

MirrorFace has disabled Windows Defender in compromised environments.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

T1685
Disable or Modify Tools
GroupBRONZE BUTLER

BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes.

T1685
Disable or Modify Tools
GroupAgrius

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.

T1685
Disable or Modify Tools
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring.

T1685
Disable or Modify Tools
GroupLazarus Group

Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services..

T1685
Disable or Modify Tools
GroupINC Ransom

INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

T1685
Disable or Modify Tools
GroupVelvet Ant

Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations.

T1685
Disable or Modify Tools
GroupPlay

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.

T1685
Disable or Modify Tools
GroupMagic Hound

Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads.

T1685
Disable or Modify Tools
MalwareHDoor

HDoor kills anti-virus found on the victim.

T1685
Disable or Modify Tools
MalwareTrickBot

TrickBot can disable Windows Defender.

T1685
Disable or Modify Tools
MalwareEKANS

EKANS stops processes related to security and management software.

T1685
Disable or Modify Tools
MalwareJumbledPath

JumbledPath can impair logging on all devices used along its connection path to compromised hosts.

T1685
Disable or Modify Tools
MalwareStuxnet

Stuxnet reduces the integrity level of objects to allow write actions.

T1685
Disable or Modify Tools
MalwareRobbinHood

RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process.

T1685
Disable or Modify Tools
MalwareStrongPity

StrongPity can add directories used by the malware to the Windows Defender exclusions list to prevent detection.

T1685
Disable or Modify Tools
MalwareBrave Prince

Brave Prince terminates antimalware processes.

T1685
Disable or Modify Tools
MalwareMedusa Ransomware

Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts.

T1685
Disable or Modify Tools
MalwaremacOS.OSAMiner

macOS.OSAMiner has searched for the Activity Monitor process in the System Events process list and kills the process if running. macOS.OSAMiner also searches the operating system's `install.log` for apps matching its hardcoded list, killing all matching process names.

T1685
Disable or Modify Tools
MalwareSslMM

SslMM identifies and kills anti-malware processes.

T1685
Disable or Modify Tools
MalwareBOLDMOVE

BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging.

T1685
Disable or Modify Tools
MalwareWoody RAT

Woody RAT has suppressed all error reporting by calling `SetErrorMode` with 0x8007 as a parameter.

T1685
Disable or Modify Tools
MalwareShrinkLocker

ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems.

T1685
Disable or Modify Tools
MalwareHildegard

Hildegard has modified DNS resolvers to evade DNS monitoring tools.

T1685
Disable or Modify Tools
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive.

T1685
Disable or Modify Tools
MalwareSkidmap

Skidmap has the ability to set SELinux to permissive mode.

T1685
Disable or Modify Tools
MalwareRaspberry Robin

Raspberry Robin can add an exception to Microsoft Defender that excludes the entire main drive from anti-malware scanning to evade detection.

T1685
Disable or Modify Tools
MalwareDiavol

Diavol can attempt to stop security software.

T1685
Disable or Modify Tools
MalwareDarkComet

DarkComet can disable Security Center functions like anti-virus.

T1685
Disable or Modify Tools
MalwareHUI Loader

HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions.

T1685
Disable or Modify Tools
MalwareRagnar Locker

Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products.

T1685
Disable or Modify Tools
MalwareAvaddon

Avaddon looks for and attempts to stop anti-malware solutions.

T1685
Disable or Modify Tools
MalwareConficker

Conficker terminates various services related to system security and Windows.

T1685
Disable or Modify Tools
MalwareLockerGoga

LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus.

T1685
Disable or Modify Tools
MalwareRunningRAT

RunningRAT kills antimalware running process.

T1685
Disable or Modify Tools
MalwareBabuk

Babuk can stop anti-virus services on a compromised host.

T1685
Disable or Modify Tools
MalwareMultiLayer Wiper

MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies.

T1685
Disable or Modify Tools
MalwareLumma Stealer

Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called.

T1685
Disable or Modify Tools
MalwarePureCrypter

PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans.

T1685
Disable or Modify Tools
MalwareDarkGate

DarkGate will terminate processes associated with several security software products if identified during execution.

T1685
Disable or Modify Tools
MalwareNanHaiShu

NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity.

T1685
Disable or Modify Tools
MalwareLockBit 3.0

LockBit 3.0 can disable security tools to evade detection including Windows Defender.

T1685
Disable or Modify Tools
MalwareThiefQuest

ThiefQuest uses the function kill_unwanted to obtain a list of running processes and kills each process matching a list of security related processes.

T1685
Disable or Modify Tools
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.