T1562.001 Disable or Modify Tools
Subtécnica de T1562 Impair Defenses
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information. Adversaries…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
SigmaHQ no tiene reglas para esta técnica.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.