Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
ToolImminent Monitor | Imminent Monitor has a feature to disable Windows Task Manager. |
| T1685 Disable or Modify Tools |
ToolDonut | Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignHomeLand Justice | During HomeLand Justice, threat actors deleted Windows events and application logs. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs. |
| T1685.001 Disable or Modify Windows Event Log |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team disabled event logging on compromised systems. |
| T1685.001 Disable or Modify Windows Event Log |
GroupMagic Hound | Magic Hound has executed scripts to disable the event log service. |
| T1685.001 Disable or Modify Windows Event Log |
GroupThreat Group-3390 | Threat Group-3390 has used appcmd.exe to disable logging on a victim server. |
| T1685.001 Disable or Modify Windows Event Log |
ToolWevtutil | Wevtutil can be used to disable specific event logs on the system. |
| T1685.002 Disable or Modify Cloud Log |
GroupAPT29 | APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants. |
| T1685.002 Disable or Modify Cloud Log |
ToolPacu | Pacu can disable or otherwise restrict various AWS logging services, such as AWS CloudTrail and VPC flow logs. |
| T1685.003 Modify or Spoof Tool UI |
MalwarePHASEJAM | PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary. |
| T1685.004 Disable or Modify Linux Audit System Log |
MalwareEbury | Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active. |
| T1685.005 Clear Windows Event Logs |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise. |
| T1685.005 Clear Windows Event Logs |
CampaignOperation Wocao | During Operation Wocao, the threat actors deleted all Windows system and security event logs using `/Q /c wevtutil cl system` and `/Q /c wevtutil cl security`. |
| T1685.005 Clear Windows Event Logs |
GroupAPT38 | APT38 clears Window Event logs and Sysmon logs from the system. |
| T1685.005 Clear Windows Event Logs |
GroupIndrik Spider | Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`. |
| T1685.005 Clear Windows Event Logs |
GroupVolt Typhoon | Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity. |
| T1685.005 Clear Windows Event Logs |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events. |
| T1685.005 Clear Windows Event Logs |
GroupDragonfly | Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys. |
| T1685.005 Clear Windows Event Logs |
GroupAPT32 | APT32 has cleared select event log entries. |
| T1685.005 Clear Windows Event Logs |
GroupHAFNIUM | HAFNIUM has cleared actor-performed actions from logs. |
| T1685.005 Clear Windows Event Logs |
GroupAquatic Panda | Aquatic Panda clears Windows Event Logs following activity to evade defenses. |
| T1685.005 Clear Windows Event Logs |
GroupFIN5 | FIN5 has cleared event logs from victims. |
| T1685.005 Clear Windows Event Logs |
GroupChimera | Chimera has cleared event logs on compromised hosts. |
| T1685.005 Clear Windows Event Logs |
GroupMirrorFace | MirrorFace has deleted Windows event logs. |
| T1685.005 Clear Windows Event Logs |
GroupAPT28 | APT28 has cleared event logs, including by using the commands |
| T1685.005 Clear Windows Event Logs |
GroupPlay | Play has used tools to remove log files on targeted systems. |
| T1685.005 Clear Windows Event Logs |
GroupFIN8 | FIN8 has cleared logs during post compromise cleanup activities. |
| T1685.005 Clear Windows Event Logs |
MalwareSynAck | SynAck clears event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareRansomHub | RansomHub can delete events from the Security, System, and Application logs. |
| T1685.005 Clear Windows Event Logs |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to clear the System and Security event logs using |
| T1685.005 Clear Windows Event Logs |
MalwareDUSTTRAP | DUSTTRAP can delete infected system log information. |
| T1685.005 Clear Windows Event Logs |
MalwareMafalda | Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions. |
| T1685.005 Clear Windows Event Logs |
MalwareShrinkLocker | ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs. |
| T1685.005 Clear Windows Event Logs |
MalwareApostle | Apostle will attempt to delete all event logs on a victim machine following file wipe activity. |
| T1685.005 Clear Windows Event Logs |
MalwareBlackCat | BlackCat can clear Windows event logs using `wevtutil.exe`. |
| T1685.005 Clear Windows Event Logs |
MalwareLucifer | Lucifer can clear and remove event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareBlackEnergy | The BlackEnergy component KillDisk is capable of deleting Windows Event Logs. |
| T1685.005 Clear Windows Event Logs |
MalwareNotPetya | NotPetya uses |
| T1685.005 Clear Windows Event Logs |
MalwareRunningRAT | RunningRAT contains code to clear event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareMultiLayer Wiper | MultiLayer Wiper removes Windows event logs during execution. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 3.0 | LockBit 3.0 can delete log files on targeted systems. |
| T1685.005 Clear Windows Event Logs |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can clear all system event logs. |
| T1685.005 Clear Windows Event Logs |
Malwaregh0st RAT | gh0st RAT is able to wipe event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWiper | HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 2.0 | LockBit 2.0 can delete log files through the use of wevtutil. |
| T1685.005 Clear Windows Event Logs |
MalwareFinFisher | FinFisher clears the system event logs using |
| T1685.005 Clear Windows Event Logs |
MalwareZxShell | ZxShell has a command to clear system event logs. |
| T1685.005 Clear Windows Event Logs |
MalwareMeteor | Meteor can use Wevtutil to remove Security, System and Application Event Viewer logs. |
| T1685.005 Clear Windows Event Logs |
MalwareKillDisk | KillDisk deletes Application, Security, Setup, and System Windows Event Logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.