ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1685×

32 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
GroupAPT38

APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools.

T1685
Disable or Modify Tools
GroupIndrik Spider

Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services.

T1685
Disable or Modify Tools
GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

T1685
Disable or Modify Tools
GroupKimsuky

Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user.

T1685
Disable or Modify Tools
GroupAPT41

APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.

T1685
Disable or Modify Tools
GroupGorgon Group

Gorgon Group malware can attempt to disable security features in Microsoft Office and Windows Defender using the taskkill command.

T1685
Disable or Modify Tools
GroupMuddyWater

MuddyWater can disable the system's local proxy settings.

T1685
Disable or Modify Tools
GroupFIN6

FIN6 has deployed a utility script named kill.bat to disable anti-virus.

T1685
Disable or Modify Tools
GroupGamaredon Group

Gamaredon Group has delivered macros which can tamper with Microsoft Office security settings.

T1685
Disable or Modify Tools
GroupTeamTNT

TeamTNT has disabled and uninstalled security tools such as Alibaba, Tencent, and BMC cloud monitoring agents on cloud-based infrastructure.

T1685
Disable or Modify Tools
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1685
Disable or Modify Tools
GroupScattered Spider

Scattered Spider has uninstalled and disabled security tools.

T1685
Disable or Modify Tools
GroupUNC3886

UNC3886 has disabled OpenSSL digital signature verification of system files through corruption of boot files.

T1685
Disable or Modify Tools
GroupContagious Interview

Contagious Interview has convinced victims to disable Docker and other container environments and run code on their machine natively in attempts to bypass container isolation and ensure device infection.

T1685
Disable or Modify Tools
GroupTA2541

TA2541 has attempted to disable built-in security protections such as Windows AMSI.

T1685
Disable or Modify Tools
GroupAkira

Akira has disabled or modified security tools for defense evasion.

T1685
Disable or Modify Tools
GroupPutter Panda

Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe).

T1685
Disable or Modify Tools
GroupAquatic Panda

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.

T1685
Disable or Modify Tools
GroupSaint Bear

Saint Bear will modify registry entries and scheduled task objects associated with Windows Defender to disable its functionality.

T1685
Disable or Modify Tools
GroupTurla

Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products.

T1685
Disable or Modify Tools
GroupTA505

TA505 has used malware to disable Windows Defender.

T1685
Disable or Modify Tools
GroupMirrorFace

MirrorFace has disabled Windows Defender in compromised environments.

T1685
Disable or Modify Tools
GroupMedusa Group

Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`. Medusa Group has also leveraged I/O control codes (IOCTLs) for terminating and deleting processes of identified security tools.

T1685
Disable or Modify Tools
GroupBRONZE BUTLER

BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes.

T1685
Disable or Modify Tools
GroupAgrius

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.

T1685
Disable or Modify Tools
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring.

T1685
Disable or Modify Tools
GroupLazarus Group

Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services..

T1685
Disable or Modify Tools
GroupINC Ransom

INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

T1685
Disable or Modify Tools
GroupVelvet Ant

Velvet Ant attempted to disable local security tools and endpoint detection and response (EDR) software during operations.

T1685
Disable or Modify Tools
GroupPlay

Play has used tools including GMER, IOBit, and PowerTool to disable antivirus software.

T1685
Disable or Modify Tools
GroupMagic Hound

Magic Hound has disabled antivirus services on targeted systems in order to upload malicious payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.