Impair Defenses T1562
Tactic: Stealth
Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as firewalls and anti-virus, but also detection capabilities that defenders can use to audit activity and identify malicious behavior. This may also span both native defenses as well as supplemental capabilities installed by users and administrators.
Events covered
37 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 468 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (306 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (2027 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (225 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 55 rules
- Attack protection features manipulation - some attack protection features have been disabled.
- Attempt To Delete A CloudTrail Log
- Attempt To Modify CloudTrail Log Settings
- Attempt To Stop CloudTrail Logging
- Audit policy disabled by command line
- Audit policy disabled by command line
- Bot detection - the feature is turned off completely or some policies.
- Breached Password Detection - critical settings manipulated
- Brute Force Protection - critical settings manipulated
- CloudTrail Log Deleted
- CloudTrail Log Settings Modified
- CloudTrail Logging Stopped
- Event log deactivation or size reduction (command)
- Excessive or unexpected Management API scope grants on applications
- Firewall deactivation (deprecated command)
- Firewall deactivation (firewall)
- Firewall deactivation (modern command)
- Firewall deactivation (PowerShell)
- Firewall Disabled
- Firewall rule added using PowerShell or CMD
- Firewall rule any/any created
- Firewall rule creation (command)
- Insecure OAuth2.x flows have been enabled for some applications
- Loaded LiquidJS error page template contains XSS vulnerabilities
- macOS System Integrity Protection Modification Attempt
- macOS TCC Database Modification
- MFA downgrade - adaptive MFA risk assessment disabled
- MFA downgrade - disable MFA policies by modifying the policies
- MFA downgrade - disable strong factors
- Microsoft Defender critical security components disabled (command)
- Microsoft Defender critical security components disabled (PowerShell)
- Microsoft Defender default action changed to allow any threat (command)
- Microsoft Defender default action changed to allow any threat (PowerShell)
- Microsoft Defender real time protection failure (native)
- Microsoft Defender security components disabled (command)
- Microsoft Defender security components disabled (PowerShell)
- Microsoft Defender service components status disabled (Registry via Sysmon)
- Microsoft Defender service deactivation attempt (command)
- Microsoft Defender threat exclusion added (native)
- Microsoft Defender threat exclusion added (PowerShell)
- NTLM downgrade attack (Reg via SYSMON)
- OCSP responder auditing settings changed or disabled
- OpenSSH server firewall configuration on Windows (command)
- OpenSSH server firewall configuration on Windows (firewall)
- OpenSSH server firewall configuration on Windows (PowerShell)
- Risk for misconfiguration - use of Auth0 tenant name URL.
- SIGKILL Sent to Security Tools
- SMB insecure guest authentication activated (native)
- SQL Server auditing deactivated
- SQL Server database auditing deactivated
- Suspicious IP Throttling - critical settings manipulated
- Unauthorized or Unexpected Enabling of Cross-Origin Authentication (CORS)
- Unrecognized IP in attack protection allowlists
- Wdigest authentication enabled (Reg via command)
- Wdigest authentication enabled (registry)
Elastic 145 rules
- AppArmor Policy Interface Access
- AppArmor Policy Violation Detected
- AppArmor Profile Compilation via apparmor_parser
- Application Removed from Blocklist in Google Workspace
- Attempt to Clear Kernel Ring Buffer
- Attempt to Clear Logs via Journalctl
- Attempt to Deactivate an Okta Network Zone
- Attempt to Deactivate an Okta Policy
- Attempt to Deactivate an Okta Policy Rule
- Attempt to Delete an Okta Network Zone
- Attempt to Delete an Okta Policy
- Attempt to Delete an Okta Policy Rule
- Attempt to Disable Auditd Service
- Attempt to Disable IPTables or Firewall
- Attempt to Disable Syslog Service
- Attempt to Modify an Okta Network Zone
- Attempt to Modify an Okta Policy
- Attempt to Modify an Okta Policy Rule
- Attempt to Unload Elastic Endpoint Security Kernel Extension
- AWS Bedrock Automated Reasoning Safety Policy Tampering
- AWS Bedrock Guardrail Deleted or Weakened
- AWS Bedrock Model Invocation Logging Disabled or Modified
- AWS CloudTrail Log Created
- AWS CloudTrail Log Deleted
- AWS CloudTrail Log Evasion
- AWS CloudTrail Log Suspended
- AWS CloudTrail Log Updated
- AWS CloudWatch Alarm Deletion
- AWS CloudWatch Log Group Deletion
- AWS CloudWatch Log Stream Deletion
- AWS Config Resource Deletion
- AWS Configuration Recorder Stopped
- AWS EC2 Network Access Control List Creation
- AWS EC2 Network Access Control List Deletion
- AWS EC2 Security Group Configuration Change
- AWS EC2 Serial Console Access Enabled
- AWS EKS Control Plane Logging Disabled
- AWS EventBridge Rule Disabled or Deleted
- AWS GuardDuty Detector Deletion
- AWS GuardDuty Member Account Manipulation
- AWS KMS Key Policy Updated via PutKeyPolicy
- AWS Route 53 Domain Transfer Lock Disabled
- AWS Route 53 Resolver Query Log Configuration Deleted
- AWS S3 Bucket Configuration Deletion
- AWS S3 Bucket Expiration Lifecycle Configuration Added
- AWS S3 Bucket Server Access Logging Disabled
- AWS SQS Queue Purge
- AWS VPC Flow Logs Deletion
- AWS WAF Access Control List Deletion
- AWS WAF Rule or Rule Group Deletion
- Azure Diagnostic Settings Alert Suppression Rule Created or Modified
- Azure Diagnostic Settings Deleted
- Azure Event Hub Deleted
- Azure Kubernetes Services (AKS) Kubernetes Events Deleted
- Azure Resource Group Deleted
- Azure VNet Firewall Front Door WAF Policy Deleted
- Azure VNet Firewall Policy Deleted
- Azure VNet Network Watcher Deleted
- BPF filter applied using TC
- BPF Program Tampering via bpftool
- Clearing Windows Event Logs
- Decline in host-based traffic
- Deprecated - M365 Exchange DLP Policy Deleted
- Deprecated - M365 Teams External Access Enabled
- Disable Windows Event and Security Logs Using Built-in Tools
- Disable Windows Firewall Rules via Netsh
- Disabling Lsa Protection via Registry Modification
- Disabling User Account Control via Registry Modification
- Disabling Windows Defender Security Settings via PowerShell
- DNS Global Query Block List Modified or Disabled
- DNS-over-HTTPS Enabled via Registry
- Domain Added to Google Workspace Trusted Domains
- Elastic Agent Service Terminated
- Elastic Defend Alert Followed by Telemetry Loss
- Enable Host Network Discovery via Netsh
- Gatekeeper Override and Execution
- GCP Firewall Rule Creation
- GCP Firewall Rule Deletion
- GCP Firewall Rule Modification
- GCP Logging Bucket Deletion
- GCP Logging Sink Deletion
- GCP Logging Sink Modification
- GCP Pub/Sub Subscription Deletion
- GCP Pub/Sub Topic Deletion
- GCP Virtual Private Cloud Network Deletion
- GCP Virtual Private Cloud Route Creation
- GCP Virtual Private Cloud Route Deletion
- GitHub App Deleted
- GitHub Protected Branch Settings Changed
- GitHub Secret Scanning Disabled
- Google Workspace Bitlocker Setting Disabled
- Google Workspace Restrictions for Marketplace Modified to Allow Any App
- High Number of Process and/or Service Terminations
- High Number of Process Terminations
- IIS HTTP Logging Disabled
- Insecure AWS EC2 VPC Security Group Ingress Rule Added
- Kerberos Pre-authentication Disabled for User
- Kernel Module Removal
- Kill Command Execution
- Kubernetes Admission Webhook Created or Modified
- Local Account TokenFilter Policy Disabled
- M365 Exchange Anti-Phish Policy Deleted
- M365 Exchange Anti-Phish Rule Modification
- M365 Exchange DKIM Signing Configuration Disabled
- M365 Exchange Email Safe Attachment Rule Disabled
- M365 Exchange Email Safe Link Policy Disabled
- M365 Exchange Mail Flow Transport Rule Modified
- M365 Exchange Mailbox Audit Logging Bypass Added
- M365 Exchange Malware Filter Policy Deleted
- M365 Exchange Malware Filter Rule Modified
- M365 Security Compliance Admin Signal
- M365 SharePoint Site Sharing Policy Weakened
- M365 Teams Custom Application Interaction Enabled
- Microsoft Windows Defender Tampering
- Modification of AmsiEnable Registry Key
- Modification of Safari Settings via Defaults Command
- Network-Level Authentication (NLA) Disabled
- Potential Antimalware Scan Interface Bypass via PowerShell
- Potential Disabling of AppArmor
- Potential Disabling of SELinux
- Potential Evasion via Filter Manager
- Potential Evasion via Windows Filtering Platform
- Potential HTTP Downgrade Attack
- Potential NetNTLMv1 Downgrade Attack
- Potential Privacy Control Bypass via TCCDB Modification
- Potential RemoteMonologue Attack
- PowerShell Script Block Logging Disabled
- PowerShell Script with Windows Defender Tampering Capabilities
- Quarantine Attrib Removed by Unsigned or Untrusted Process
- Remote Desktop Enabled in Windows Firewall by Netsh
- Scheduled Tasks AT Command Enabled
- SELinux Configuration Creation or Renaming
- Sensitive Audit Policy Sub-Category Disabled
- Service Disabled via Registry Modification
- SoftwareUpdate Preferences Modification
- SolarWinds Process Disabling Services via Registry
- Suspicious Antimalware Scan Interface DLL
- Suspicious Kernel Feature Activity
- Suspicious Sysctl File Event
- Suspicious Write Attempt to AppArmor Policy Management Files
- Tampering with RUNNER_TRACKING_ID in GitHub Actions Runners
- WDAC Policy File by an Unusual Process
- Windows Defender Disabled via Registry Modification
- Windows Defender Exclusions Added via PowerShell
- Windows Firewall Disabled via PowerShell
Splunk 25 rules
- Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal
- Cisco IOS XE VTY Access Class Tampering
- Defender Registry Values Modified (Sysmon)
- Defender Registry Values Modified (Windows Event Log)
- ETW Trace Provider Modified - PowerShell (PowerShell)
- Modify Windows Defender (EDR)
- Modify Windows Defender (PowerShell)
- Modify Windows Defender (Sysmon)
- Modify Windows Defender (Windows Event Log)
- Service Stop Commands (PowerShell)
- Service Stop Commands (Sysmon)
- Service Stop Commands (Windows Event Log)
- WFP Blocked Connection from EDR Agent (Windows Event Log)
- WFP Filter and Provider Changed (Windows Event Log)
- Windows - Service Stop (PowerShell)
- Windows - Service Stop (Windows Event Log)
- Windows Defender Disabled Detection (EDR)
- Windows Defender Disabled Detection (PowerShell)
- Windows Defender Disabled Detection (Sysmon)
- Windows Defender Disabled Detection (Windows Event Log)
- Windows Firewall Disabled (PowerShell)
- Windows Firewall Disabled (Sysmon)
- Windows Firewall Disabled (Windows Event Log)
- Windows Firewall Rule Creation (PowerShell)
- Windows Firewall Rule Creation (Windows Event Log)
Kusto 103 rules
- AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
- AWSCloudTrail - Amazon ECR image scanning disabled
- AWSCloudTrail - AWS GuardDuty detector disabled or suspended
- AWSCloudTrail - Changes to Amazon VPC settings
- AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups
- AWSCloudTrail - Changes to AWS Security Group ingress and egress settings
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Config Service Resource Deletion Attempts
- AWSCloudTrail - Network ACL with all the open ports to a specified CIDR
- AWSCloudTrail - Tampering to AWS CloudTrail logs
- Azure DevOps Audit Stream Disabled
- Azure Diagnostic settings removed from a resource
- BTP - Audit log service unavailable
- Check Point Exposure Management - Alert Ingestion Anomaly
- Cisco SE - Policy update failure
- CiscoISE - Log collector was suspended
- Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed)
- Conditional Access - A Conditional Access policy was deleted
- Conditional Access - A Conditional Access policy was disabled
- Conditional Access - A Conditional Access policy was put into report-only mode
- Conditional Access - A Conditional Access policy was updated
- Conditional Access - A new Conditional Access policy was created
- Copilot - File Uploads Disabled
- Copilot - Plugin Tampering (Enable and Disable Within 5 Minutes)
- Critical or High Severity Detections by User
- CTERA Mass Access Denied Detection Analytic
- Dataverse - Audit logging disabled
- Deleted a Custom Field Mapping profile
- Deleted a Tenant
- Detect Windows Allow Firewall Rule Addition/Modification
- Detect Windows Update Disabled from Registry
- Dev-0270 Malicious Powershell usage
- Disable or Modify Windows Defender
- Disabling Security Services via Registry
- Doppelpaymer Stop Services
- Excessive Denied Proxy Traffic
- Exchange AuditLog Disabled
- Firewall rule manipulation attempts stateful anomaly on database
- GCP Audit Logs - Data Access Logging Exemption Added for Principal
- GCP Audit Logs - Detect Bulk VM Snapshot Deletion
- GCP Audit Logs - Detect Organization Policy Deletion or Updation
- GCP Audit Logs - DNSSEC Disabled on Managed DNS Zone
- GCP Audit Logs - Open Firewall Rule Created or Modified
- GCP Audit Logs - VPC Flow Logs Disabled
- GCP IAM - Disable Data Access Logging
- GCP Security Command Center - Detect DNSSEC disabled for DNS zones
- GCP Security Command Center - Detect Resources with Logging Disabled
- GitHub Two Factor Auth Disable
- Illumio Enforcement Change Analytic Rule
- Illumio Firewall Tampering Analytic Rule
- Illumio VEN Clone Detection Rule
- Illumio VEN Deactivated Detection Rule
- Illumio VEN Offline Detection Rule
- Illumio VEN Suspend Detection Rule
- Imminent Ransomware
- McAfee ePO - Agent Handler down
- McAfee ePO - Attempt uninstall McAfee agent
- McAfee ePO - Deployment failed
- McAfee ePO - Error sending alert
- McAfee ePO - File added to exceptions
- McAfee ePO - Firewall disabled
- McAfee ePO - Logging error occurred
- McAfee ePO - Multiple threats on same host
- McAfee ePO - Scanning engine disabled
- McAfee ePO - Task error
- McAfee ePO - Threat was not blocked
- McAfee ePO - Unable to clean or delete infected file
- McAfee ePO - Update failed
- MosaicLoader
- Netskope - Repeated or Critical Policy Violations
- NRT Azure DevOps Audit Stream Disabled
- NRT GitHub Two Factor Auth Disable
- Office Policy Tampering
- Pathlock TDnR - ABAP Source Code Changes
- Pathlock TDnR - Authorization Check Value Changes (SU24)
- Pathlock TDnR - Critical File Integrity Changes
- Pathlock TDnR - DDIC Table Utility Changes (SE14)
- Pathlock TDnR - Generic SAP Change Documents
- Pathlock TDnR - Generic Table Content Changes
- Pathlock TDnR - Global System Change Setting Events
- Pathlock TDnR - ICM Security Events
- Pathlock TDnR - SAP Client Configuration Changes
- Pathlock TDnR - SAP HANA Parameter Changes
- Pathlock TDnR - SAP Instance Profile Changes
- Pathlock TDnR - SAP Security Audit Log Events
- Pathlock TDnR - SE16N Direct Table Change Documents
- Pathlock TDnR - SU24 Table USOBT_C Changes
- Pathlock TDnR - SU24 Table USOBX_C Changes
- Pathlock TDnR - Switchable Authorization Design Changes
- Pathlock TDnR - Switchable Authorization Runtime Changes
- Pathlock TDnR - System Security Policy Changes
- Pathlock TDnR - Table Parameter Setting Changes
- Pathlock TDnR - User Authorization Buffer Manipulation
- Power Automate - Unusual bulk deletion of flow resources
- Scheduled Task Hide
- Security Service Registry ACL Modification
- Starting or Stopping HealthService to Avoid Detection
- Stopping multiple processes using taskkill
- Trend Micro CAS - Threat detected and not blocked
- Valimail Enforce - DMARC Policy Weakened to None
- Valimail Enforce - Email Authentication Key Deleted
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions
- Zero Networks Segement - Machine Removed from protection
YARA-L 36 rules
- AWS Account Leaving Or Removed From The Organization
- AWS CloudTrail Logging Tampered
- AWS Config Service Modified
- AWS Delete CloudWatch Log Group
- AWS Delete VPC Flow Logs
- AWS GuardDuty Disabled
- AWS GuardDuty Publishing Destination Deleted
- AWS GuardDuty Trusted Or Threat IP Lists Tampered
- AWS IAM Access Analyzer Deleted
- AWS S3 Bucket Made Public By ACL
- AWS S3 Public Access Block Removed
- AWS Security Group Open To The World
- GCP BigQuery Datasets Opened To Public
- GCP Cloud Audit Logging Removed From All Services
- GCP Exempt Principals From Audit Log
- GCP Firewall Rule Opened To The World
- GCP Security Command Center Service Disabled
- GCP Storage Bucket Opened To Public
- GitHub Dependabot Vulnerability Alerts Disabled
- GitHub Enterprise Audit Log Stream Destroyed
- GitHub Enterprise Audit Log Stream Modified
- GitHub Personal Access Token Auto Approve Policy Modified
- GitHub Repository Branch Protection Rules Disabled
- GitHub Secret Scanning Disabled Or Bypassed
- GitHub SSO Configuration Modified
- GitHub Two-Factor Authentication Requirement Disabled
- Google Workspace Marketplace Allowlist Configuration
- Google Workspace New Trusted Domain Added
- Office 365 logging has been enabled
- Office 365 logging is disabled
- Reg Add Suspicious Paths
- sap deactivation of security audit log
- sap hanadb audit trail policy changes
- sap hanadb deactivation of audit trail
- sap security audit log configuration change
- sap system or client configuration change
Panther 104 rules
- A User from the company domain(s) Logged in without SAML
- Account Security Configuration Changed
- Anthropic IP Restriction Deleted
- Anthropic MCP Server Deleted
- Anthropic Organization Settings Updated
- Anthropic SSO Disabled
- AppOmni Alert Passthrough
- Auth0 Attack Protection Monitoring Disabled
- Auth0 Bot Detection Policy Disabled
- AWS ACM Secure Algorithms
- AWS Bedrock Guardrail Updated or Deleted
- AWS Bedrock Model Invocation Logging Configuration Deleted
- AWS CloudTrail Attempt To Leave Org
- AWS CloudTrail CloudWatch Logs
- AWS CloudTrail Least Privilege Access
- AWS CloudTrail Log Validation
- AWS CloudTrail Management Events Enabled
- AWS CloudTrail Retention Lifecycle Too Short
- AWS Config Service Disabled
- AWS DNS Logs Deleted
- AWS EC2 Instance Detailed Monitoring
- AWS EC2 Manual Security Group Change
- AWS GuardDuty Enabled
- AWS GuardDuty Master Account
- AWS Macie Disabled/Updated
- AWS RDS Activity Stream Stopped
- AWS RDS Deletion Protection Disabled
- AWS RDS Instance Modified to be Publicly Accessible
- AWS RDS Security Group Ingress Authorized
- AWS Redshift Cluster Logging
- AWS S3 Bucket Logging
- AWS S3 Security Control Disabling
- AWS S3 Security Controls Disabled
- AWS SecurityHub Finding Evasion
- AWS Trusted IPSet Modified
- AWS VPC Flow Logs
- AWS VPC Flow Logs Removed
- AWS WAF Disassociation
- AWS WAF Logging Configured
- Azure Action Groups Deleted
- Azure Alert Rules Deleted
- Azure Alert Suppression Rule Created or Modified
- Azure Diagnostic Settings Deleted
- Azure Event Hub Deleted
- Azure Firewall Policy Deleted
- Azure Log Analytics Workspace Deleted
- Azure Network Security Configuration Modified or Deleted
- Azure Network Watcher Deleted
- Azure Recovery Services Protection Container Deleted
- Azure Resource Lock Deleted
- Azure Storage Immutability Policy Deleted
- Carbon Black Data Forwarder Stopped
- CloudTrail Event Selectors Disabled
- CloudTrail Stopped
- Databricks Delta Sharing Recipient Without IP ACLs
- Databricks High Priority Configuration Changes
- Databricks Verbose Audit Logging Disabled
- Detection content has been deleted from Panther
- EC2 Network ACL Modified
- EC2 Network Gateway Modified
- EC2 Security Group Modified
- EC2 VPC Modified
- GCP Cloud Storage Buckets Modified Or Deleted
- GCP KMS Key Granted to GCS Service Account
- GCP KMS Key Version Disabled or Destroyed
- GitHub Advanced Security Change WITHOUT Repo Archived
- GitHub Repository Ruleset Modified
- GitHub Security Change, includes GitHub Advanced Security
- GSuite User Advanced Protection Change
- Kubernetes Pod Using Host IPC Namespace
- Kubernetes Role With Node Proxy Permissions Created
- MacOS ALF is misconfigured
- MongoDB logging toggled
- MongoDB security alerts disabled or deleted
- OpenAI IP Allowlist Configuration Changes
- OpenAI SCIM Configuration Change
- OSQuery Reports Application Firewall Disabled
- Panther SAML configuration has been modified
- S3 Bucket Encryption Deleted
- S3 Bucket Logging Disabled
- S3 Bucket Replication Deleted
- S3 Bucket Versioning Suspended
- S3 MFA Delete Disabled
- S3 Public Access Block Deleted
- Sensitive API Calls Via VPC Endpoint
- Slack DLP Modified
- Slack EKM Config Changed
- Slack Information Barrier Modified
- Slack Legal Hold Policy Modified
- Slack Microsoft Intune Mobile Device Management Disabled
- Sublime Mailbox Deactivated
- Sublime Message Source Deleted Or Deactivated
- Sublime Rules Deleted Or Deactivated
- Upwind Posture Detection Passthrough
- Wiz CICD Scan Policy Updated Or Deleted
- Wiz Connector Updated Or Deleted
- Wiz Data Classifier Updated Or Deleted
- Wiz Image Integrity Validator Updated Or Deleted
- Wiz Integration Updated Or Deleted
- Wiz Rule Change
- Wiz Update Scanner Settings
- ZIA Backup Deleted
- ZIA Golden Restore Point Dropped
- ZIA Log Streaming Disabled