Real-world descriptions of how a group, tool or campaign used a technique.
32 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685 Disable or Modify Tools |
GroupAPT38 | APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools. |
| T1685 Disable or Modify Tools |
GroupIndrik Spider | Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services. |
| T1685 Disable or Modify Tools |
GroupBlackByte | BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations. |
| T1685 Disable or Modify Tools |
GroupKimsuky | Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user. |
| T1685 Disable or Modify Tools |
GroupAPT41 | APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging. |
| T1685 Disable or Modify Tools |
GroupGorgon Group | Gorgon Group malware can attempt to disable security features in Microsoft Office and Windows Defender using the |
| T1685 Disable or Modify Tools |
GroupMuddyWater | MuddyWater can disable the system's local proxy settings. |
| T1685 Disable or Modify Tools |
GroupFIN6 | FIN6 has deployed a utility script named |
| T1685 Disable or Modify Tools |
GroupGamaredon Group | Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings. |
| T1685 Disable or Modify Tools |
GroupTeamTNT | TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure. |
| T1685 Disable or Modify Tools |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1685 Disable or Modify Tools |
GroupScattered Spider | Scattered Spider has uninstalled and disabled security tools. |
| T1685 Disable or Modify Tools |
GroupUNC3886 | UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files. |
| T1685 Disable or Modify Tools |
GroupContagious Interview | Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection. |
| T1685 Disable or Modify Tools |
GroupTA2541 | TA2541 has attempted to disable built-in security protections such as Windows AMSI. |
| T1685 Disable or Modify Tools |
GroupAkira | Akira has disabled or modified security tools for defense evasion. |
| T1685 Disable or Modify Tools |
GroupPutter Panda | Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe). |
| T1685 Disable or Modify Tools |
GroupAquatic Panda | Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems. |
| T1685 Disable or Modify Tools |
GroupSaint Bear | Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality. |
| T1685 Disable or Modify Tools |
GroupTurla | Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products. |
| T1685 Disable or Modify Tools |
GroupTA505 | TA505 has used malware to disable Windows Defender. |
| T1685 Disable or Modify Tools |
GroupMirrorFace | MirrorFace has disabled Windows Defender in compromised environments. |
| T1685 Disable or Modify Tools |
GroupMedusa Group | Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools. |
| T1685 Disable or Modify Tools |
GroupBRONZE BUTLER | BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes. |
| T1685 Disable or Modify Tools |
GroupAgrius | Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, |
| T1685 Disable or Modify Tools |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring. |
| T1685 Disable or Modify Tools |
GroupLazarus Group | Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services.. |
| T1685 Disable or Modify Tools |
GroupINC Ransom | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
| T1685 Disable or Modify Tools |
GroupVelvet Ant | Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations. |
| T1685 Disable or Modify Tools |
GroupPlay | Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software. |
| T1685 Disable or Modify Tools |
GroupMagic Hound | Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.