Real-world descriptions of how a group, tool or campaign used a technique.
9 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
CampaignKV Botnet Activity | KV Botnet Activity used various scripts to remove or disable security tools, such as |
| T1685 Disable or Modify Tools |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell. |
| T1685 Disable or Modify Tools |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry internet settings to lower internet security. |
| T1685 Disable or Modify Tools |
CampaignCutting Edge | During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection. |
| T1685 Disable or Modify Tools |
CampaignHomeLand Justice | During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus. |
| T1685 Disable or Modify Tools |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products. |
| T1685 Disable or Modify Tools |
CampaignArcaneDoor | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations. |
| T1685 Disable or Modify Tools |
CampaignNight Dragon | During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet. |
| T1685 Disable or Modify Tools |
CampaignQuad7 Activity | Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.