Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
GroupAquatic Panda | Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems. |
| T1685 Disable or Modify Tools |
GroupSaint Bear | Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality. |
| T1685 Disable or Modify Tools |
GroupTurla | Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products. |
| T1685 Disable or Modify Tools |
GroupTA505 | TA505 has used malware to disable Windows Defender. |
| T1685 Disable or Modify Tools |
GroupMirrorFace | MirrorFace has disabled Windows Defender in compromised environments. |
| T1685 Disable or Modify Tools |
GroupMedusa Group | Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools. |
| T1685 Disable or Modify Tools |
GroupBRONZE BUTLER | BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes. |
| T1685 Disable or Modify Tools |
GroupAgrius | Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, |
| T1685 Disable or Modify Tools |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring. |
| T1685 Disable or Modify Tools |
GroupLazarus Group | Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services.. |
| T1685 Disable or Modify Tools |
GroupINC Ransom | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
| T1685 Disable or Modify Tools |
GroupVelvet Ant | Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations. |
| T1685 Disable or Modify Tools |
GroupPlay | Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software. |
| T1685 Disable or Modify Tools |
GroupMagic Hound | Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads. |
| T1685 Disable or Modify Tools |
MalwareHDoor | HDoor kills anti-virus found on the victim. |
| T1685 Disable or Modify Tools |
MalwareTrickBot | TrickBot can disable Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareEKANS | EKANS stops processes related to security and management software. |
| T1685 Disable or Modify Tools |
MalwareJumbledPath | JumbledPath can impair logging on all devices used along its connection path to compromised hosts. |
| T1685 Disable or Modify Tools |
MalwareStuxnet | Stuxnet reduces the integrity level of objects to allow write actions. |
| T1685 Disable or Modify Tools |
MalwareRobbinHood | RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process. |
| T1685 Disable or Modify Tools |
MalwareStrongPity | StrongPity can add directories used by the malware to the Windows Defender exclusions list to prevent detection. |
| T1685 Disable or Modify Tools |
MalwareBrave Prince | Brave Prince terminates antimalware processes. |
| T1685 Disable or Modify Tools |
MalwareMedusa Ransomware | Medusa Ransomware has terminated antivirus services utilizing the gaze.exe executable. Medusa Ransomware has also terminated antivirus services utilizing PowerShell scripts. |
| T1685 Disable or Modify Tools |
MalwaremacOS.OSAMiner | macOS.OSAMiner has searched for the Activity Monitor process in the System Events process list and kills the process if running. macOS.OSAMiner also searches the operating system's `install.log` for apps matching its hardcoded list, killing all matching process names. |
| T1685 Disable or Modify Tools |
MalwareSslMM | SslMM identifies and kills anti-malware processes. |
| T1685 Disable or Modify Tools |
MalwareBOLDMOVE | BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging. |
| T1685 Disable or Modify Tools |
MalwareWoody RAT | Woody RAT has suppressed all error reporting by calling `SetErrorMode` with 0x8007 as a parameter. |
| T1685 Disable or Modify Tools |
MalwareShrinkLocker | ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems. |
| T1685 Disable or Modify Tools |
MalwareHildegard | Hildegard has modified DNS resolvers to evade DNS monitoring tools. |
| T1685 Disable or Modify Tools |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive. |
| T1685 Disable or Modify Tools |
MalwareSkidmap | Skidmap has the ability to set SELinux to permissive mode. |
| T1685 Disable or Modify Tools |
MalwareRaspberry Robin | Raspberry Robin can add an exception to Microsoft Defender that excludes the entire main drive from anti-malware scanning to evade detection. |
| T1685 Disable or Modify Tools |
MalwareDiavol | Diavol can attempt to stop security software. |
| T1685 Disable or Modify Tools |
MalwareDarkComet | DarkComet can disable Security Center functions like anti-virus. |
| T1685 Disable or Modify Tools |
MalwareHUI Loader | HUI Loader has the ability to disable Windows Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) functions. |
| T1685 Disable or Modify Tools |
MalwareRagnar Locker | Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products. |
| T1685 Disable or Modify Tools |
MalwareAvaddon | Avaddon looks for and attempts to stop anti-malware solutions. |
| T1685 Disable or Modify Tools |
MalwareConficker | Conficker terminates various services related to system security and Windows. |
| T1685 Disable or Modify Tools |
MalwareLockerGoga | LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus. |
| T1685 Disable or Modify Tools |
MalwareRunningRAT | RunningRAT kills antimalware running process. |
| T1685 Disable or Modify Tools |
MalwareBabuk | Babuk can stop anti-virus services on a compromised host. |
| T1685 Disable or Modify Tools |
MalwareMultiLayer Wiper | MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies. |
| T1685 Disable or Modify Tools |
MalwareLumma Stealer | Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called. |
| T1685 Disable or Modify Tools |
MalwarePureCrypter | PureCrypter has executed `Set-MpPreference -ExclusionPath` to exclude files or folders from Windows Defender scans. |
| T1685 Disable or Modify Tools |
MalwareDarkGate | DarkGate will terminate processes associated with several security software products if identified during execution. |
| T1685 Disable or Modify Tools |
MalwareNanHaiShu | NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity. |
| T1685 Disable or Modify Tools |
MalwareLockBit 3.0 | LockBit 3.0 can disable security tools to evade detection including Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareThiefQuest | ThiefQuest uses the function |
| T1685 Disable or Modify Tools |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.