Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · defense-impairment

T1685 Disable or Modify Tools

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys,…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 81.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.