Tactic.View on attack.mitre.org
The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.
Defense Impairment consists of techniques that degrade, disable, or undermine the effectiveness and trustworthiness of security controls and monitoring mechanisms. These techniques are characterized by direct interference with defensive systems. The goal is to reduce defenders’ ability to detect, interpret, or respond to adversary activity.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1112 | Modify Registry | 0 | 173 |
| T1207 | Rogue Domain Controller | 0 | 1 |
| T1222 | File and Directory Permissions Modification | 2 | 28 |
| T1484 | Domain or Tenant Policy Modification | 2 | 20 |
| T1553 | Subvert Trust Controls | 6 | 112 |
| T1556 | Modify Authentication Process | 9 | 25 |
| T1578 | Modify Cloud Compute Infrastructure | 5 | 6 |
| T1599 | Network Boundary Bridging | 1 | 2 |
| T1600 | Weaken Encryption | 2 | 0 |
| T1601 | Modify System Image | 2 | 2 |
| T1647 | Plist File Modification | 0 | 2 |
| T1666 | Modify Cloud Resource Hierarchy | 0 | 0 |
| T1685 | Disable or Modify Tools | 6 | 188 |
| T1686 | Disable or Modify System Firewall | 3 | 52 |
| T1687 | Exploitation for Defense Impairment | 0 | 0 |
| T1688 | Safe Mode Boot | 0 | 7 |
| T1689 | Downgrade Attack | 0 | 3 |
| T1690 | Prevent Command History Logging | 0 | 12 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.