Disable or Modify Tools

T1685

Technique with 6 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion).

More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.

Detection rules353

Rules on DetectionCode tagged with T1685 or one of its sub-techniques.

Sigma192

RuleLevelLog sourceTechnique
Add SafeBoot Keys Via Reg Utilityhighwindows / process_creationT1685
AMSI Bypass Pattern Assembly GetTypehighwindows / ps_scriptT1685
AMSI Disabled via Registry Modificationhighwindows / registry_setT1685
Antivirus Filter Driver Disallowed On Dev Drive - Registryhighwindows / registry_setT1685
ASLR Disabled Via Sysctl or Direct Syscall - Linuxhighlinux / NULLT1685
Audit Policy Tampering Via Auditpolhighwindows / process_creationT1685.001
Audit Policy Tampering Via NT Resource Kit Auditpolhighwindows / process_creationT1685.001
Audit Rules Deleted Via Auditctlhighlinux / process_creationT1685.004
Auditing Configuration Changes on Linux Hosthighlinux / NULLT1685
AWS Config Disabling Channel/Recorderhighaws / NULLT1685.002
AWS GuardDuty Detector Deleted Or Updatedhighaws / NULLT1685 T1685.002
AWS GuardDuty Important Changehighaws / NULLT1685
AWS SecurityHub Findings Evasionhighaws / NULLT1685
Bitbucket Secret Scanning Exempt Repository Addedhighbitbucket / NULLT1685
Change Winevt Channel Access Permission Via Registryhighwindows / registry_setT1685.001

Splunk161

RuleTypeRiskData sourceTechnique
Add or Set Windows Defender ExclusionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1685
ASL AWS Defense Evasion Delete CloudtrailTTPNULLASL AWS CloudTrailT1685.002
ASL AWS Defense Evasion Delete CloudWatch Log GroupTTPNULLASL AWS CloudTrailT1685.002
ASL AWS Defense Evasion Impair Security ServicesHuntingNULLASL AWS CloudTrailT1685.002
ASL AWS Defense Evasion PutBucketLifecycleHuntingNULLASL AWS CloudTrailT1685.002
ASL AWS Defense Evasion Stop Logging CloudtrailTTPNULLASL AWS CloudTrailT1685.002
ASL AWS Defense Evasion Update CloudtrailTTPNULLASL AWS CloudTrailT1685.002
AWS Bedrock Delete GuardRailsTTPNULLAWS CloudTrail DeleteGuardrailT1685.002
AWS Bedrock Delete Model Invocation Logging ConfigurationTTPNULLAWS CloudTrail DeleteModelInvocationLoggingConfigurationT1685.002
AWS Defense Evasion Delete CloudtrailTTPNULLAWS CloudTrail DeleteTrailT1685.002
AWS Defense Evasion Delete CloudWatch Log GroupTTPNULLAWS CloudTrail DeleteLogGroupT1685.002
AWS Defense Evasion Impair Security ServicesTTPNULLAWS CloudTrail DeleteLogStream, AWS CloudTrail DeleteDetector, AWS CloudTrail DeleteIPSet, AWS CloudTrail DeleteWebACL, AWS CloudTrail DeleteRule, AWS CloudTrail DeleteRuleGroup, AWS CloudTrail DeleteLoggingConfiguration, AWS CloudTrail DeleteAlarmsT1685.002
AWS Defense Evasion PutBucketLifecycleHuntingNULLAWS CloudTrail PutBucketLifecycleT1685.002
AWS Defense Evasion Stop Logging CloudtrailTTPNULLAWS CloudTrail StopLoggingT1685.002
AWS Defense Evasion Update CloudtrailTTPNULLAWS CloudTrail UpdateTrailT1685.002

Sub-techniques6

IDNameExamples
T1685.001Disable or Modify Windows Event Log6
T1685.002Disable or Modify Cloud Log2
T1685.003Modify or Spoof Tool UI1
T1685.004Disable or Modify Linux Audit System Log1
T1685.005Clear Windows Event Logs42
T1685.006Clear Linux or Mac System Logs8

Groups32

Show 8 more

Software87

Show 63 more

Campaigns9

Procedure examples128

Groups32

Used byProcedure example
GroupAgrius

Agrius used several mechanisms to try to disable security tools. Agrius attempted to modify EDR-related services to disable auto-start on system reboot. Agrius used a publicly available driver, GMER64.sys typically used for anti-rootkit functionality, to selectively stop and remove security software processes.

GroupAkira

Akira has disabled or modified security tools for defense evasion.

GroupAPT38

APT38 has unhooked DLLs to disable endpoint detection and response (EDR) or anti-virus (AV) tools.

GroupAPT41

APT41 developed a custom injector that enables an Event Tracing for Windows (ETW) bypass, making malicious processes invisible to Windows logging.

GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring.

GroupAquatic Panda

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.

GroupBlackByte

BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.

GroupBRONZE BUTLER

BRONZE BUTLER has incorporated code into several tools that attempts to terminate anti-virus processes.

View all 32 groups examples

Software87

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has the capability to kill any running analysis processes and AV software.

MalwareAvaddon

Avaddon looks for and attempts to stop anti-malware solutions.

MalwareBabuk

Babuk can stop anti-virus services on a compromised host.

MalwareBazar

Bazar has manually loaded ntdll from disk in order to identity and remove API hooks set by security products.

MalwareBlackByte Ransomware

BlackByte Ransomware adds .JS and .EXE extensions to the Microsoft Defender exclusion list. BlackByte Ransomware terminates and removes the Raccine anti-ransomware utility.

MalwareBOLDMOVE

BOLDMOVE can disable the Fortinet daemons `moglogd` and `syslogd` to evade detection and logging.

MalwareBrave Prince

Brave Prince terminates antimalware processes.

ToolBrute Ratel C4

Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI).

View all 87 software examples

Campaigns9

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry internet settings to lower internet security.

CampaignArcaneDoor

ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations.

CampaignCutting Edge

During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection.

CampaignHomeLand Justice

During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus.

CampaignKV Botnet Activity

KV Botnet Activity used various scripts to remove or disable security tools, such as http_watchdog and firewallsd, as well as tools related to other botnet infections, such as mips_ff, on victim devices.

CampaignNight Dragon

During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet.

CampaignQuad7 Activity

Quad7 Activity has disabled the TP-Link management interface for TP-Link by killing the /usr/bin/httpd process.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors disabled Microsoft Defender through Registry settings and real-time monitoring via PowerShell.

View all 9 campaigns examples

References4

  1. Cocomazzi FIN7 Reboot Open source
    Cocomazzi, Antonio. (2024, July 17). FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks. Retrieved September 24, 2025.
  2. ETW Palantir Open source
    Palantir. (2018, December 24). Tampering with Windows Event Tracing: Background, Offense, and Defense. Retrieved April 15, 2026.
  3. Microsoft Lamin Sept 2017 Open source
    Microsoft. (2009, May 17). Backdoor:Win32/Lamin.A. Retrieved September 6, 2018.
  4. SCADAfence_ransomware Open source
    Shaked, O. (2020, January 20). Anatomy of a Targeted Ransomware Attack. Retrieved June 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.