Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1684.001 Impersonation |
GroupTeamPCP | TeamPCP impersonated legitimate maintainers to push imposter commits to the Aquasecurity Trivy scanner GitHub repository. |
| T1685 Disable or Modify Tools |
GroupAPT38 | APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools. |
| T1685 Disable or Modify Tools |
GroupIndrik Spider | Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
| T1685 Disable or Modify Tools |
GroupKimsuky | Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user. |
| T1685 Disable or Modify Tools |
GroupAPT41 | APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging. |
| T1685 Disable or Modify Tools |
GroupGorgon Group | Gorgon Group malware can attempt to disable security features in Microsoft Office and Windows Defender using the |
| T1685 Disable or Modify Tools |
GroupMuddyWater | MuddyWater can disable the system's local proxy settings. |
| T1685 Disable or Modify Tools |
GroupFIN6 | FIN6 has deployed a utility script named |
| T1685 Disable or Modify Tools |
GroupGamaredon Group | Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings. |
| T1685 Disable or Modify Tools |
GroupTeamTNT | TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure. |
| T1685 Disable or Modify Tools |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1685 Disable or Modify Tools |
GroupScattered Spider | Scattered Spider has uninstalled and disabled security tools. |
| T1685 Disable or Modify Tools |
GroupUNC3886 | UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files. |
| T1685 Disable or Modify Tools |
GroupContagious Interview | Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection. |
| T1685 Disable or Modify Tools |
GroupTA2541 | TA2541 has attempted to disable built-in security protections such as Windows AMSI. |
| T1685 Disable or Modify Tools |
GroupAkira | Akira has disabled or modified security tools for defense evasion. |
| T1685 Disable or Modify Tools |
GroupPutter Panda | Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe). |
| T1685 Disable or Modify Tools |
GroupAquatic Panda | Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems. |
| T1685 Disable or Modify Tools |
GroupSaint Bear | Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality. |
| T1685 Disable or Modify Tools |
GroupTurla | Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products. |
| T1685 Disable or Modify Tools |
GroupTA505 | TA505 has used malware to disable Windows Defender. |
| T1685 Disable or Modify Tools |
GroupMirrorFace | MirrorFace has disabled Windows Defender in compromised environments. |
| T1685 Disable or Modify Tools |
GroupMedusa Group | Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools. |
| T1685 Disable or Modify Tools |
GroupBRONZE BUTLER | BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes. |
| T1685 Disable or Modify Tools |
GroupAgrius | Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, |
| T1685 Disable or Modify Tools |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring. |
| T1685 Disable or Modify Tools |
GroupLazarus Group | Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services.. |
| T1685 Disable or Modify Tools |
GroupINC Ransom | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
| T1685 Disable or Modify Tools |
GroupVelvet Ant | Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations. |
| T1685 Disable or Modify Tools |
GroupPlay | Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software. |
| T1685 Disable or Modify Tools |
GroupMagic Hound | Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads. |
| T1685.001 Disable or Modify Windows Event Log |
GroupMagic Hound | Magic Hound has executed scripts to disable the event log service. |
| T1685.001 Disable or Modify Windows Event Log |
GroupThreat Group-3390 | Threat Group-3390 has used appcmd.exe to disable logging on a victim server. |
| T1685.002 Disable or Modify Cloud Log |
GroupAPT29 | APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants. |
| T1685.005 Clear Windows Event Logs |
GroupAPT38 | APT38 clears Window Event logs and Sysmon logs from the system. |
| T1685.005 Clear Windows Event Logs |
GroupIndrik Spider | Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`. |
| T1685.005 Clear Windows Event Logs |
GroupVolt Typhoon | Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity. |
| T1685.005 Clear Windows Event Logs |
GroupAPT41 | APT41 attempted to remove evidence of some of its activity by clearing Windows security and system events. |
| T1685.005 Clear Windows Event Logs |
GroupDragonfly | Dragonfly has cleared Windows event logs and other logs produced by tools they used, including system, security, terminal services, remote services, and audit logs. The actors also deleted specific Registry keys. |
| T1685.005 Clear Windows Event Logs |
GroupAPT32 | APT32 has cleared select event log entries. |
| T1685.005 Clear Windows Event Logs |
GroupHAFNIUM | HAFNIUM has cleared actor-performed actions from logs. |
| T1685.005 Clear Windows Event Logs |
GroupAquatic Panda | Aquatic Panda clears Windows Event Logs following activity to evade defenses. |
| T1685.005 Clear Windows Event Logs |
GroupFIN5 | FIN5 has cleared event logs from victims. |
| T1685.005 Clear Windows Event Logs |
GroupChimera | Chimera has cleared event logs on compromised hosts. |
| T1685.005 Clear Windows Event Logs |
GroupMirrorFace | MirrorFace has deleted Windows event logs. |
| T1685.005 Clear Windows Event Logs |
GroupAPT28 | APT28 has cleared event logs, including by using the commands |
| T1685.005 Clear Windows Event Logs |
GroupPlay | Play has used tools to remove log files on targeted systems. |
| T1685.005 Clear Windows Event Logs |
GroupFIN8 | FIN8 has cleared logs during post compromise cleanup activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.