ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1684.001
Impersonation
GroupTeamPCP

TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository.

T1685
Disable or Modify Tools
GroupAPT38

APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools.

T1685
Disable or Modify Tools
GroupIndrik Spider

Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services.

T1685
Disable or Modify Tools
GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

T1685
Disable or Modify Tools
GroupKimsuky

Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user.

T1685
Disable or Modify Tools
GroupAPT41

APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.

T1685
Disable or Modify Tools
GroupGorgon Group

Gorgon Group malware can attempt to disable security features in Microsoft Office and Windows Defender using the taskkill command.

T1685
Disable or Modify Tools
GroupMuddyWater

MuddyWater can disable the system's local proxy settings.

T1685
Disable or Modify Tools
GroupFIN6

FIN6 has deployed a utility script named kill.bat to disable anti-virus.

T1685
Disable or Modify Tools
GroupGamaredon Group

Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings.

T1685
Disable or Modify Tools
GroupTeamTNT

TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure.

T1685
Disable or Modify Tools
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1685
Disable or Modify Tools
GroupScattered Spider

Scattered Spider has uninstalled and disabled security tools.

T1685
Disable or Modify Tools
GroupUNC3886

UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files.

T1685
Disable or Modify Tools
GroupContagious Interview

Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection.

T1685
Disable or Modify Tools
GroupTA2541

TA2541 has attempted to disable built-in security protections such as Windows AMSI.

T1685
Disable or Modify Tools
GroupAkira

Akira has disabled or modified security tools for defense evasion.

T1685
Disable or Modify Tools
GroupPutter Panda

Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe).

T1685
Disable or Modify Tools
GroupAquatic Panda

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.

T1685
Disable or Modify Tools
GroupSaint Bear

Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality.

T1685
Disable or Modify Tools
GroupTurla

Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products.

T1685
Disable or Modify Tools
GroupTA505

TA505 has used malware to disable Windows Defender.

T1685
Disable or Modify Tools
GroupMirrorFace

MirrorFace has disabled Windows Defender in compromised environments.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

T1685
Disable or Modify Tools
GroupBRONZE BUTLER

BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes.

T1685
Disable or Modify Tools
GroupAgrius

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.

T1685
Disable or Modify Tools
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring.

T1685
Disable or Modify Tools
GroupLazarus Group

Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services..

T1685
Disable or Modify Tools
GroupINC Ransom

INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

T1685
Disable or Modify Tools
GroupVelvet Ant

Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations.

T1685
Disable or Modify Tools
GroupPlay

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.

T1685
Disable or Modify Tools
GroupMagic Hound

Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads.

T1685.001
Disable or Modify Windows Event Log
GroupMagic Hound

Magic Hound has executed scripts to disable the event log service.

T1685.001
Disable or Modify Windows Event Log
GroupThreat Group-3390

Threat Group-3390 has used appcmd.exe to disable logging on a victim server.

T1685.002
Disable or Modify Cloud Log
GroupAPT29

APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants.

T1685.005
Clear Windows Event Logs
GroupAPT38

APT38 clears Window Event logs and Sysmon logs from the system.

T1685.005
Clear Windows Event Logs
GroupIndrik Spider

Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`.

T1685.005
Clear Windows Event Logs
GroupVolt Typhoon

Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity.

T1685.005
Clear Windows Event Logs
GroupAPT41

APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events.

T1685.005
Clear Windows Event Logs
GroupDragonfly

Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys.

T1685.005
Clear Windows Event Logs
GroupAPT32

APT32 has cleared select event log entries.

T1685.005
Clear Windows Event Logs
GroupHAFNIUM

HAFNIUM has cleared actor-performed actions from logs.

T1685.005
Clear Windows Event Logs
GroupAquatic Panda

Aquatic Panda clears Windows Event Logs following activity to evade defenses.

T1685.005
Clear Windows Event Logs
GroupFIN5

FIN5 has cleared event logs from victims.

T1685.005
Clear Windows Event Logs
GroupChimera

Chimera has cleared event logs on compromised hosts.

T1685.005
Clear Windows Event Logs
GroupMirrorFace

MirrorFace has deleted Windows event logs.

T1685.005
Clear Windows Event Logs
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

T1685.005
Clear Windows Event Logs
GroupPlay

Play has used tools to remove log files on targeted systems.

T1685.005
Clear Windows Event Logs
GroupFIN8

FIN8 has cleared logs during post compromise cleanup activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.