Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
MalwareBundlore | Bundlore can change browser security settings to enable extensions to be installed. Bundlore uses the |
| T1685 Disable or Modify Tools |
MalwareMetamorfo | Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching. |
| T1685 Disable or Modify Tools |
MalwareRedLine Stealer | RedLine Stealer can disable security software and update services. |
| T1685 Disable or Modify Tools |
MalwareMegaCortex | MegaCortex was used to kill endpoint security processes. |
| T1685 Disable or Modify Tools |
MalwareBlackByte Ransomware | BlackByte Ransomware adds .JS and .EXE extensions to the Microsoft Defender exclusion list. BlackByte Ransomware terminates and removes the Raccine anti-ransomware utility. |
| T1685 Disable or Modify Tools |
MalwareGrandoreiro | Grandoreiro can hook APIs, kill processes, break file system paths, and change ACLs to prevent security tools from running. |
| T1685 Disable or Modify Tools |
MalwareBazar | Bazar has manually loaded ntdll from disk in order to identity and remove API hooks set by security products. |
| T1685 Disable or Modify Tools |
MalwareXLoader | XLoader loads a copy of NTDLL to evade hooks from security monitoring tools on this library. XLoader can add the path of its executable to the Microsoft Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareRyuk | Ryuk has stopped services related to anti-virus. |
| T1685 Disable or Modify Tools |
MalwareHermeticWiper | HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps. |
| T1685 Disable or Modify Tools |
MalwarePysa | Pysa has the capability to stop antivirus services and disable Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareLockBit 2.0 | LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareCobalt Strike | Cobalt Strike has the ability to use Smart Applet attacks to disable the Java SecurityManager sandbox. |
| T1685 Disable or Modify Tools |
MalwareSUNBURST | SUNBURST attempted to disable software security services following checks against a FNV-1a + XOR hashed hardcoded blocklist. |
| T1685 Disable or Modify Tools |
MalwareUnknown Logger | Unknown Logger has functionality to disable security tools, including Kaspersky, BitDefender, and MalwareBytes. |
| T1685 Disable or Modify Tools |
MalwareREvil | REvil can connect to and disable the Symantec server on the victim's network. |
| T1685 Disable or Modify Tools |
MalwareNanoCore | NanoCore can modify the victim's anti-virus. |
| T1685 Disable or Modify Tools |
MalwareGold Dragon | Gold Dragon terminates anti-malware processes if they’re found running on the system. |
| T1685 Disable or Modify Tools |
MalwareCarberp | Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed. |
| T1685 Disable or Modify Tools |
MalwareTinyZBot | TinyZBot can disable Avira anti-virus. |
| T1685 Disable or Modify Tools |
MalwareProton | Proton kills security tools like Wireshark that are running. |
| T1685 Disable or Modify Tools |
MalwareMango | Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process. |
| T1685 Disable or Modify Tools |
MalwarePHASEJAM | PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file. |
| T1685 Disable or Modify Tools |
MalwareClop | Clop can uninstall or disable security products. |
| T1685 Disable or Modify Tools |
MalwareEgregor | Egregor has disabled Windows Defender to evade protections. |
| T1685 Disable or Modify Tools |
MalwareStealBit | StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`. |
| T1685 Disable or Modify Tools |
MalwareZxShell | ZxShell can kill AV products' processes. |
| T1685 Disable or Modify Tools |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection. |
| T1685 Disable or Modify Tools |
MalwareEbury | Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules. |
| T1685 Disable or Modify Tools |
MalwareMeteor | Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareZIPLINE | ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process. |
| T1685 Disable or Modify Tools |
MalwareMaze | Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services. |
| T1685 Disable or Modify Tools |
MalwareChChes | ChChes can alter the victim's proxy configuration. |
| T1685 Disable or Modify Tools |
MalwareShai-Hulud | Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`. |
| T1685 Disable or Modify Tools |
MalwareJPIN | JPIN can lower security settings by changing Registry keys. |
| T1685 Disable or Modify Tools |
MalwareKOCTOPUS | KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials. |
| T1685 Disable or Modify Tools |
MalwareQilin | Qilin can terminate antivirus-related processes and services. |
| T1685 Disable or Modify Tools |
MalwareLazyWiper | LazyWiper can disable Microsoft Windows Defender Real-Time Monitoring with the `Set-MpPreference` cmdlet. |
| T1685 Disable or Modify Tools |
MalwareAgent Tesla | Agent Tesla has the capability to kill any running analysis processes and AV software. |
| T1685 Disable or Modify Tools |
MalwarePOWERSTATS | POWERSTATS can disable Microsoft Office Protected View by changing Registry keys. |
| T1685 Disable or Modify Tools |
MalwareDRYHOOK | DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated. |
| T1685 Disable or Modify Tools |
MalwareGoopy | Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings. |
| T1685 Disable or Modify Tools |
MalwareQakBot | QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list. |
| T1685 Disable or Modify Tools |
MalwareSplatCloak | SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky. |
| T1685 Disable or Modify Tools |
MalwareWaterbear | Waterbear can hook the |
| T1685 Disable or Modify Tools |
MalwareH1N1 | H1N1 kills and disables services for Windows Security Center, and Windows Defender. |
| T1685 Disable or Modify Tools |
MalwareWarzoneRAT | WarzoneRAT can disarm Windows Defender during the UAC process to evade detection. |
| T1685 Disable or Modify Tools |
ToolSILENTTRINITY | SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions. |
| T1685 Disable or Modify Tools |
ToolDCRAT | DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection. |
| T1685 Disable or Modify Tools |
ToolBrute Ratel C4 | Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.