Technique.View on attack.mitre.org
Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of a system’s backward compatibility to force it into less secure modes of operation.
Adversaries may downgrade and use various less-secure versions of features of a system, such as Command and Scripting Interpreter or even network protocols that can be abused to enable Adversary-in-the-Middle or Network Sniffing. For example, PowerShell versions 5+ includes Script Block Logging (SBL), which can record executed script content. However, adversaries may attempt to execute a previous version of PowerShell that does not support SBL with the intent to impair defenses while running malicious scripts that may have otherwise been detected.
Adversaries may similarly target network traffic to downgrade from an encrypted HTTPS connection to an unsecured HTTP connection that exposes network data in clear text. On Windows systems, adversaries may downgrade the boot manager to a vulnerable version that bypasses Secure Boot, granting the ability to disable various operating system security mechanisms.
Rules on DetectionCode tagged with T1689.
| Rule | Level | Log source |
|---|---|---|
| LSA PPL Protection Setting Modification via CommandLine | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| PowerShell 4104 Hunting | Hunting | NULL | Powershell Script Block Logging 4104 |
| Windows Downdate Registry Activity | Anomaly | NULL | Sysmon EventID 12, Sysmon EventID 13, Sysmon EventID 14 |
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareBlackByte Ransomware | BlackByte Ransomware enables SMBv1 during execution. |
| ToolSILENTTRINITY | SILENTTRINITY can downgrade NTLM to capture NTLM hashes. |
| Used by | Procedure example |
|---|---|
| CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.