Disable or Modify Tools T1685
Tactic: Defense Impairment
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Events covered
76 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 916 rules share fields, values, and exclusions.
Fields filtered most (441 distinct)
These fields appear most often in rule filters.
Top indicator values (4438 distinct)
These values appear most often in rule predicates.
Exclusions (970 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 262 rules
- Add SafeBoot Keys Via Reg Utility
- AMSI Bypass Pattern Assembly GetType
- AMSI Disabled via Registry Modification
- Antivirus Filter Driver Disallowed On Dev Drive - Registry
- ASLR Disabled Via Sysctl or Direct Syscall - Linux
- Attack protection features manipulation - some attack protection features have been disabled.
- Attempt To Delete A CloudTrail Log
- Attempt To Modify CloudTrail Log Settings
- Attempt To Stop CloudTrail Logging
- Audit policy disabled by command line
- Audit policy disabled by command line
- Audit Policy Tampering Via Auditpol
- Audit Policy Tampering Via NT Resource Kit Auditpol
- Audit Rules Deleted Via Auditctl
- Auditing Configuration Changes on Linux Host
- AWS Bedrock Guardrail Deleted
- AWS Bedrock Guardrail Updated
- AWS CloudTrail Important Change
- AWS Config Disabling Channel/Recorder
- AWS GuardDuty Detector Deleted Or Updated
- AWS GuardDuty Important Change
- AWS SecurityHub Findings Evasion
- Azure Kubernetes Events Deleted
- Bitbucket Audit Log Configuration Updated
- Bitbucket Global Secret Scanning Rule Deleted
- Bitbucket Global SSH Settings Changed
- Bitbucket Project Secret Scanning Allowlist Added
- Bitbucket Secret Scanning Exempt Repository Added
- Bitbucket Secret Scanning Rule Deleted
- Bot detection - the feature is turned off completely or some policies.
- Breached Password Detection - critical settings manipulated
- Brute Force Protection - critical settings manipulated
- Change Winevt Channel Access Permission Via Registry
- Cisco Disabling Logging
- Cisco Dot1x Disabled
- Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
- CloudTrail Log Deleted
- CloudTrail Log Settings Modified
- CloudTrail Logging Stopped
- Devcon Execution Disabling VMware VMCI Device
- Diamond Sleet APT Scheduled Task Creation - Registry
- Disable Exploit Guard Network Protection on Windows Defender
- Disable of ETW Trace - Powershell
- Disable Or Stop Services
- Disable Privacy Settings Experience in Registry
- Disable PUA Protection on Windows Defender
- Disable Security Events Logging Adding Reg Key MiniNt
- Disable Security Tools
- Disable Tamper Protection on Windows Defender
- Disable Windows Defender AV Security Monitoring
- Disable Windows Defender Functionalities Via Registry Keys
- Disable Windows Event Logging Via Registry
- Disable Windows IIS HTTP Logging
- Disable-WindowsOptionalFeature Command PowerShell
- Disabled IE Security Features
- Disabled Volume Snapshots
- Disabled Windows Defender Eventlog
- Disabling Windows Defender WMI Autologger Session via Reg.exe
- Dism Remove Online Package
- Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
- ESXi Syslog Configuration Change Via ESXCLI
- ETW Logging Disabled For rpcrt4.dll
- ETW Logging Disabled For SCM
- ETW Logging Disabled In .NET Processes - Registry
- ETW Logging Disabled In .NET Processes - Sysmon Registry
- ETW Logging Tamper In .NET Processes Via CommandLine
- ETW Logging/Processing Option Disabled On IIS Server
- ETW Trace Evasion Activity
- Event log clear attempt (command)
- Event log clear attempt (PowerShell)
- Event log clear attempt (wmi)
- Event log cleared (native)
- Event log cleared using Diagnostics (via PowerShell)
- Event log deactivation or size reduction (command)
- Eventlog Cleared
- EVTX Created In Uncommon Location
- Excessive or unexpected Management API scope grants on applications
- Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
- Filter Driver Unloaded Via Fltmc.EXE
- Firewall deactivation (deprecated command)
- Firewall deactivation (firewall)
- Firewall deactivation (modern command)
- Firewall deactivation (PowerShell)
- Firewall Disabled
- Firewall rule added using PowerShell or CMD
- Firewall rule any/any created
- Firewall rule creation (command)
- Folder Removed From Exploit Guard ProtectedFolders List - Registry
- Forest Blizzard APT - File Creation Activity
- Forest Blizzard APT - JavaScript Constrained File Creation
- Github Push Protection Bypass Detected
- Github Push Protection Disabled
- Github Secret Scanning Feature Disabled
- Google Cloud Firewall Modified or Deleted
- HackTool - CobaltStrike BOF Injection Pattern
- Hacktool - EDR-Freeze Execution
- HackTool - EDRSilencer Execution
- HackTool - EDRSilencer Execution - Filter Added
- HackTool - PowerTool Execution
- HackTool - SharpEvtMute DLL Load
- HackTool - SharpEvtMute Execution
- HackTool - Stracciatella Execution
- HackTool - SysmonEnte Execution
- Hide Schedule Task Via Index Value Tamper
- HTTP Logging Disabled On IIS Server
- Hypervisor Enforced Paging Translation Disabled
- Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
- Important Windows Event Auditing Disabled
- Important Windows Eventlog Cleared
- Indicator Removal on Host - Clear Mac System Logs
- Insecure OAuth2.x flows have been enabled for some applications
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux
- Linux Logs Clearing Attempts
- Load Of RstrtMgr.DLL By A Suspicious Process
- Load Of RstrtMgr.DLL By An Uncommon Process
- Loaded LiquidJS error page template contains XSS vulnerabilities
- Logging Configuration Changes on Linux Host
- macOS System Integrity Protection Modification Attempt
- macOS TCC Database Modification
- MFA downgrade - adaptive MFA risk assessment disabled
- MFA downgrade - disable MFA policies by modifying the policies
- MFA downgrade - disable strong factors
- Microsoft Defender critical security components disabled (command)
- Microsoft Defender critical security components disabled (PowerShell)
- Microsoft Defender default action changed to allow any threat (command)
- Microsoft Defender default action changed to allow any threat (PowerShell)
- Microsoft Defender real time protection failure (native)
- Microsoft Defender security components disabled (command)
- Microsoft Defender security components disabled (PowerShell)
- Microsoft Defender service components status disabled (Registry via Sysmon)
- Microsoft Defender service deactivation attempt (command)
- Microsoft Defender Tamper Protection Trigger
- Microsoft Defender threat exclusion added (native)
- Microsoft Defender threat exclusion added (PowerShell)
- Microsoft Malware Protection Engine Crash
- Microsoft Malware Protection Engine Crash - WER
- Microsoft Office Protected View Disabled
- NetNTLM Downgrade Attack
- NetNTLM Downgrade Attack - Registry
- New Module Module Added To IIS Server
- NotPetya Ransomware Activity
- NTLM downgrade attack (Reg via SYSMON)
- Obfuscated PowerShell OneLiner Execution
- OCSP responder auditing settings changed or disabled
- Okta User Session Start Via An Anonymising Proxy Service
- OpenSSH server firewall configuration on Windows (command)
- OpenSSH server firewall configuration on Windows (firewall)
- OpenSSH server firewall configuration on Windows (PowerShell)
- Potential AMSI Bypass Script Using NULL Bits
- Potential AMSI Bypass Using NULL Bits
- Potential AMSI Bypass Via .NET Reflection
- Potential AMSI COM Server Hijacking
- Potential AutoLogger Sessions Tampering
- Potential EventLog File Location Tampering
- Potential Ke3chang/TidePool Malware Activity
- Potential Privileged System Service Operation - SeLoadDriverPrivilege
- Potential Suspicious Activity Using SeCEdit
- Potential Tampering With Security Products Via WMIC
- Potential Windows Defender Tampering Via Wmic.EXE
- Powershell Base64 Encoded MpPreference Cmdlet
- Powershell Defender Disable Scan Feature
- Powershell Defender Exclusion
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
- PPL Tampering Via WerFaultSecure
- Previously Installed IIS Module Was Removed
- PUA - CleanWipe Execution
- Python Function Execution Security Warning Disabled In Excel
- Python Function Execution Security Warning Disabled In Excel - Registry
- Raccine Uninstall
- RedSun - Named Pipe Created
- RedSun - TieringEngineService.exe Detected as EICAR Test File
- Reg Add Suspicious Paths
- Removal Of AMSI Provider Registry Keys
- Removal Of Index Value to Hide Schedule Task - Registry
- Removal Of SD Value to Hide Schedule Task - Registry
- Risk for misconfiguration - use of Auth0 tenant name URL.
- SafeBoot Registry Key Deleted Via Reg.EXE
- Scripted Diagnostics Turn Off Check Enabled - Registry
- Security Event Logging Disabled via MiniNt Registry Key - Process
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set
- Security Eventlog Cleared
- Security Service Disabled Via Reg.EXE
- Service Registry Key Deleted Via Reg.EXE
- Service Startup Type Change Via Wmic.EXE
- Service StartupType Change Via PowerShell Set-Service
- Service StartupType Change Via Sc.EXE
- SIGKILL Sent to Security Tools
- SMB insecure guest authentication activated (native)
- SQL Server auditing deactivated
- SQL Server database auditing deactivated
- Suspicious Application Allowed Through Exploit Guard
- Suspicious Eventlog Clear
- Suspicious Eventlog Clearing or Configuration Change Activity
- Suspicious IP Throttling - critical settings manipulated
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
- Suspicious Path In Keyboard Layout IME File Registry Value
- Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
- Suspicious PROCEXP152.sys File Created In TMP
- Suspicious Service Installed
- Suspicious Svchost Process Access
- Suspicious Uninstall of Windows Defender Feature via PowerShell
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
- Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
- Suspicious Windows Service Tampering
- Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
- Sysinternals PsSuspend Suspicious Execution
- Syslog Clearing or Removal Via System Utilities
- Sysmon Application Crashed
- Sysmon Configuration Update
- Sysmon Driver Altitude Change
- Sysmon Driver Unloaded Via Fltmc.EXE
- Tamper Windows Defender - PSClassic
- Tamper Windows Defender - ScriptBlockLogging
- Tamper Windows Defender Remove-MpPreference
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
- Tamper With Sophos AV Registry Keys
- Taskkill Symantec Endpoint Protection
- Terminate Linux Process Via Kill
- Unauthorized or Unexpected Enabling of Cross-Origin Authentication (CORS)
- Uncommon Extension In Keyboard Layout IME File Registry Value
- Uninstall Crowdstrike Falcon Sensor
- Uninstall Sysinternals Sysmon
- Unrecognized IP in attack protection allowlists
- Vulnerable Driver Blocklist Registry Tampering Via CommandLine
- WDAC Policy File Creation In CodeIntegrity Folder
- Wdigest authentication enabled (Reg via command)
- Wdigest authentication enabled (registry)
- Weak Encryption Enabled and Kerberoast
- WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze
- WFP Filter Added via Registry
- Win Defender Restored Quarantine File
- Windows AMSI Related Registry Tampering Via CommandLine
- Windows Credential Guard Disabled - Registry
- Windows Credential Guard Registry Tampering Via CommandLine
- Windows Credential Guard Related Registry Value Deleted - Registry
- Windows Defender Configuration Changes
- Windows Defender Context Menu Removed
- Windows Defender Definition Files Removed
- Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
- Windows Defender Exclusion List Modified
- Windows Defender Exclusion Registry Key - Write Access Requested
- Windows Defender Exclusions Added
- Windows Defender Exclusions Added - PowerShell
- Windows Defender Exclusions Added - Registry
- Windows Defender Exploit Guard Tamper
- Windows Defender Grace Period Expired
- Windows Defender Malware And PUA Scanning Disabled
- Windows Defender Real-time Protection Disabled
- Windows Defender Real-Time Protection Failure/Restart
- Windows Defender Service Disabled - Registry
- Windows Defender Submit Sample Feature Disabled
- Windows Defender Threat Detection Service Disabled
- Windows Defender Threat Severity Default Action Modified
- Windows Defender Virus Scanning Feature Disabled
- Windows Event Auditing Disabled
- Windows EventLog Autologger Session Registry Modification Via CommandLine
- Windows Filtering Platform Blocked Connection From EDR Agent Binary
- Windows Firewall Disabled via PowerShell
- Windows Hypervisor Enforced Code Integrity Disabled
- Windows Vulnerable Driver Blocklist Disabled
- Write Protect For Storage Disabled
Elastic 217 rules
- AllowProtectedRenames Registry Modification
- AMSI Bypass from Suspicious Module
- AMSI Bypass via COM Registry Modification
- AMSI Bypass via PowerShell
- AMSI Bypass via Unbacked Memory
- AMSI or WLDP Bypass via Memory Patching
- AppArmor Policy Interface Access
- AppArmor Policy Violation Detected
- AppArmor Profile Compilation via apparmor_parser
- Application Removed from Blocklist in Google Workspace
- Attempt to Clear Kernel Ring Buffer
- Attempt to Clear Kernel Ring Buffer via Dmesg
- Attempt to Clear Logs via Journalctl
- Attempt to Clear Logs via Journalctl
- Attempt to Deactivate an Okta Network Zone
- Attempt to Deactivate an Okta Policy
- Attempt to Deactivate an Okta Policy Rule
- Attempt to Delete an Okta Network Zone
- Attempt to Delete an Okta Policy
- Attempt to Delete an Okta Policy Rule
- Attempt to Disable Auditd Service
- Attempt to Disable Auditd Service
- Attempt to Disable IPTables or Firewall
- Attempt to Disable SELinux
- Attempt to Disable Syslog Service
- Attempt to Disable Windows Defender Services
- Attempt to Modify an Okta Network Zone
- Attempt to Modify an Okta Policy
- Attempt to Modify an Okta Policy Rule
- Attempt to Unload Elastic Endpoint Security Kernel Extension
- Auditctl Disabled via Shell Process
- AWS Attempt to Leave Organization
- AWS Backup Vault Deleted or Vault Lock Removed
- AWS Bedrock API Key Used for Destructive or Anti-Recovery Action
- AWS Bedrock Automated Reasoning Safety Policy Tampering
- AWS Bedrock Guardrail Deleted or Weakened
- AWS Bedrock Model Invocation Logging Disabled or Modified
- AWS CloudTrail Log Created
- AWS CloudTrail Log Deleted
- AWS CloudTrail Log Evasion
- AWS CloudTrail Log Suspended
- AWS CloudTrail Log Updated
- AWS CloudTrail Management Events Disabled via PutEventSelectors
- AWS CloudWatch Alarm Deletion
- AWS CloudWatch Log Group Deletion
- AWS CloudWatch Log Stream Deletion
- AWS Config Resource Deletion
- AWS Configuration Recorder Stopped
- AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity
- AWS EC2 Network Access Control List Creation
- AWS EC2 Network Access Control List Deletion
- AWS EC2 Security Group Configuration Change
- AWS EC2 Serial Console Access Enabled
- AWS EKS Control Plane Logging Disabled
- AWS EventBridge Rule Disabled or Deleted
- AWS GuardDuty Detection Suppression
- AWS GuardDuty Detector Deletion
- AWS GuardDuty Member Account Manipulation
- AWS IAM Permission Boundary or Guardrail Policy Deleted by Unusual Identity
- AWS KMS Key Policy Updated via PutKeyPolicy
- AWS Route 53 Domain Transfer Lock Disabled
- AWS Route 53 Resolver Query Log Configuration Deleted
- AWS S3 Bucket Configuration Deletion
- AWS S3 Bucket Expiration Lifecycle Configuration Added
- AWS S3 Bucket Server Access Logging Disabled
- AWS SQS Queue Purge
- AWS VPC Flow Logs Deletion
- AWS WAF Access Control List Deletion
- AWS WAF Rule or Rule Group Deletion
- Azure Diagnostic Settings Alert Suppression Rule Created or Modified
- Azure Diagnostic Settings Deleted
- Azure Event Hub Deleted
- Azure Kubernetes Services (AKS) Kubernetes Events Deleted
- Azure Resource Group Deleted
- Azure VNet Firewall Front Door WAF Policy Deleted
- Azure VNet Firewall Policy Deleted
- Azure VNet Network Watcher Deleted
- BPF filter applied using TC
- BPF Filter Applied using Traffic Control
- BPF Program Tampering via bpftool
- Clearing Windows Event Logs
- Decline in host-based traffic
- Defense Evasion via Registry Modification
- Deprecated - M365 Exchange DLP Policy Deleted
- Deprecated - M365 Teams External Access Enabled
- Disable Windows Event and Security Logs Using Built-in Tools
- Disable Windows Firewall Rules via Netsh
- Disabling Lsa Protection via Registry Modification
- Disabling User Account Control via Registry Modification
- Disabling Windows Defender Security Settings via PowerShell
- DNS Global Query Block List Modified or Disabled
- DNS-over-HTTPS Enabled via Registry
- Domain Added to Google Workspace Trusted Domains
- Elastic Agent Service Terminated
- Elastic Defend Alert Followed by Telemetry Loss
- Elastic Endpoint Security Kernel Extension Unload
- Enable Host Network Discovery via Netsh
- Endpoint Security Evasion via Malicious AppLocker Deny Rules
- Evasion via Event Tracing for Windows Patching
- File Creation in /var/log via Suspicious Process
- Firewall Policy Changed by a Suspicious Process
- Gatekeeper Override and Execution
- GCP Firewall Rule Creation
- GCP Firewall Rule Deletion
- GCP Firewall Rule Modification
- GCP Logging Bucket Deletion
- GCP Logging Sink Deletion
- GCP Logging Sink Modification
- GCP Pub/Sub Subscription Deletion
- GCP Pub/Sub Topic Deletion
- GCP Virtual Private Cloud Network Deletion
- GCP Virtual Private Cloud Route Creation
- GCP Virtual Private Cloud Route Deletion
- GenAI CLI Started with Unsafe Permission Bypass
- GitHub Actions Runner with Disabled Telemetry
- GitHub App Deleted
- GitHub Protected Branch Settings Changed
- GitHub Secret Scanning Disabled
- GKE Admission Webhook Created or Modified
- Google Workspace Bitlocker Setting Disabled
- Google Workspace Restrictions for Marketplace Modified to Allow Any App
- High Number of Process and/or Service Terminations
- High Number of Process Terminations
- IIS HTTP Logging Disabled
- Insecure AWS EC2 VPC Security Group Ingress Rule Added
- Kerberos Pre-authentication Disabled for User
- Kernel Module Removal
- Kill Command Executed from Binary in Unusual Location
- Kill Command Execution
- Killall Execution via Python
- Kubernetes Admission Webhook Created or Modified
- Loadable Kernel Module Load Followed by Log Clearing
- Local Account TokenFilter Policy Disabled
- M365 Exchange Anti-Phish Policy Deleted
- M365 Exchange Anti-Phish Rule Modification
- M365 Exchange DKIM Signing Configuration Disabled
- M365 Exchange Email Safe Attachment Rule Disabled
- M365 Exchange Email Safe Link Policy Disabled
- M365 Exchange Mail Flow Transport Rule Modified
- M365 Exchange Mailbox Audit Logging Bypass Added
- M365 Exchange Malware Filter Policy Deleted
- M365 Exchange Malware Filter Rule Modified
- M365 Security Compliance Admin Signal
- M365 SharePoint Site Sharing Policy Weakened
- M365 Teams Custom Application Interaction Enabled
- Microsoft Windows Defender Tampering
- Modification of AmsiEnable Registry Key
- Modification of Safari Settings via Defaults Command
- Modification of Safari Settings via Defaults Command
- Multiple System Log Files Deletion
- Network-Level Authentication (NLA) Disabled
- NotificationCenter Silenced via Killall Binary
- Operating System Security Updates Disabled
- Potential AMSI Bypass via RPC Runtime Hooking
- Potential AMSI Bypass via SetThreadContext
- Potential Antimalware Scan Interface Bypass via PowerShell
- Potential CVE-2024-21338 Exploitation
- Potential Defense Evasion via Filter Manager Control Program
- Potential Disabling of AppArmor
- Potential Disabling of AppArmor
- Potential Disabling of SELinux
- Potential EDR-Freeze via WerFaultSecure Abuse
- Potential Elastic Tampering via PendingFileRename
- Potential Endpoint Security Evasion via FirewallRules
- Potential ETW Bypass via VirtualProtect
- Potential Evasion via ClipUp Execution
- Potential Evasion via Filter Manager
- Potential Evasion via Stack Rumbling
- Potential Evasion via Windows Filtering Platform
- Potential HTTP Downgrade Attack
- Potential LogonUser API Hooking
- Potential NetNTLMv1 Downgrade Attack
- Potential Privacy Control Bypass via TCCDB Modification
- Potential Privilege Escalation via RoguePlanet Windows Defender Exploit
- Potential RemoteMonologue Attack
- PowerShell Script Block Logging Disabled
- PowerShell Script with Log Clear Capabilities
- PowerShell Script with Windows Defender Tampering Capabilities
- Process Creation with Unusual Mitigation
- Process Explorer Device Access by Unusual Process
- Process Suspended via TTD Monitor Driver
- QoS Policy Group Policy Registry Overwrite via WMI
- Quarantine Attrib Removed by Unsigned or Untrusted Process
- Quarantine Attribute Removal via TextEdit
- Remote Desktop Enabled in Windows Firewall by Netsh
- Scheduled Tasks AT Command Enabled
- SELinux Configuration Creation or Renaming
- Sensitive Audit Policy Sub-Category Disabled
- Service Disabled via Registry Modification
- SoftwareUpdate Preferences Modification
- SolarWinds Process Disabling Services via Registry
- Suspicious Access to AppArmor Policy Management Files
- Suspicious Antimalware Scan Interface DLL
- Suspicious Antivirus Registration
- Suspicious Crypto Wallet Process Termination
- Suspicious Kernel Feature Activity
- Suspicious Pseudo-Terminal Proxy Execution via su
- Suspicious Remote Process Suspend Activity
- Suspicious Sysctl File Event
- Suspicious Unload of Elastic Agent via Launchctl
- Suspicious Windows Defender Exclusions Added via PowerShell
- Suspicious Windows Defender Registry Modification
- Suspicious Write Attempt to AppArmor Policy Management Files
- System Log File Deletion
- Tampering with RUNNER_TRACKING_ID in GitHub Actions Runners
- Thread Suspension from Unbacked Memory
- Unusual Windows System Service Disabled
- User Account Control Disabled via Registry
- WDAC Policy File by an Unusual Process
- Windows Defender Disabled via Registry Modification
- Windows Defender Exclusions Added via PowerShell
- Windows Defender Exclusions by Extension
- Windows Defender Exclusions by Path
- Windows Defender Exclusions via WMI
- Windows Event Logs Cleared
- Windows Firewall Disabled via PowerShell
- Windows Firewall Exception List Modified via Untrusted Process
Splunk 188 rules
- Add or Set Windows Defender Exclusion
- ASL AWS Defense Evasion Delete Cloudtrail
- ASL AWS Defense Evasion Delete CloudWatch Log Group
- ASL AWS Defense Evasion Impair Security Services
- ASL AWS Defense Evasion PutBucketLifecycle
- ASL AWS Defense Evasion Stop Logging Cloudtrail
- ASL AWS Defense Evasion Update Cloudtrail
- AWS Bedrock Delete GuardRails
- AWS Bedrock Delete Model Invocation Logging Configuration
- AWS Defense Evasion Delete Cloudtrail
- AWS Defense Evasion Delete CloudWatch Log Group
- AWS Defense Evasion Impair Security Services
- AWS Defense Evasion PutBucketLifecycle
- AWS Defense Evasion Stop Logging Cloudtrail
- AWS Defense Evasion Update Cloudtrail
- Azure AD Block User Consent For Risky Apps Disabled
- Cisco ASA - Core Syslog Message Volume Drop
- Cisco ASA - Logging Disabled via CLI
- Cisco ASA - Logging Filters Configuration Tampering
- Cisco ASA - Logging Message Suppression
- Cisco Configuration Archive Logging Analysis
- Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal
- Cisco IOS XE VTY Access Class Tampering
- Cisco SNMP Community String Configuration Changes
- Clear Linux System Logs
- Clear Windows Event Logs (PowerShell)
- Clear Windows Event Logs (Windows Event Log)
- Defender Registry Values Modified (PowerShell)
- Defender Registry Values Modified (Sysmon)
- Defender Registry Values Modified (Windows Event Log)
- Disable AMSI Through Registry
- Disable Defender AntiVirus Registry
- Disable Defender BlockAtFirstSeen Feature
- Disable Defender Enhanced Notification
- Disable Defender MpEngine Registry
- Disable Defender Spynet Reporting
- Disable Defender Submit Samples Consent Feature
- Disable ETW Through Registry
- Disable Logs Using WevtUtil
- Disable Registry Tool
- Disable Schedule Task
- Disable Show Hidden Files
- Disable Windows App Hotkeys
- Disable Windows Behavior Monitoring
- Disable Windows SmartScreen Protection
- Disabling CMD Application
- Disabling ControlPanel
- Disabling Defender Services
- Disabling Firewall with Netsh
- Disabling FolderOptions Windows Feature
- Disabling NoRun Windows App
- Disabling Task Manager
- ESXi Download Errors
- ESXi Encryption Settings Modified
- ESXi Lockdown Mode Disabled
- ESXi Loghost Config Tampering
- ESXi VIB Acceptance Level Tampering
- ETW Registry Disabled
- ETW Trace Provider Modified - PowerShell (PowerShell)
- Excessive number of service control start as disabled
- Excessive Usage Of Taskkill
- GitHub Enterprise Delete Branch Ruleset
- GitHub Enterprise Disable 2FA Requirement
- GitHub Enterprise Disable Audit Log Event Stream
- GitHub Enterprise Disable Classic Branch Protection Rule
- GitHub Enterprise Disable Dependabot
- GitHub Enterprise Disable IP Allow List
- GitHub Enterprise Modify Audit Log Event Stream
- GitHub Enterprise Pause Audit Log Event Stream
- GitHub Enterprise Register Self Hosted Runner
- GitHub Organizations Delete Branch Ruleset
- GitHub Organizations Disable 2FA Requirement
- GitHub Organizations Disable Classic Branch Protection Rule
- GitHub Organizations Disable Dependabot
- Hide User Account From Sign-In Screen
- Linux Auditd Auditd Daemon Abort
- Linux Auditd Auditd Daemon Shutdown
- Linux Auditd Auditd Daemon Start
- Linux Impair Defenses Process Kill
- M365 Copilot Agentic Jailbreak Attack
- M365 Copilot Impersonation Jailbreak Attack
- M365 Copilot Information Extraction Jailbreak Attack
- M365 Copilot Jailbreak Attempts
- M365 Copilot Non Compliant Devices Accessing M365 Copilot
- Microsoft Intune DeviceManagementConfigurationPolicies
- Modify Windows Defender (PowerShell)
- Modify Windows Defender (Sysmon)
- Modify Windows Defender (Windows Event Log)
- O365 Advanced Audit Disabled
- O365 Block User Consent For Risky Apps Disabled
- O365 Email Security Feature Changed
- Powershell Disable Security Monitoring
- Powershell Remove Windows Defender Directory
- Powershell Windows Defender Exclusion Commands
- Process Kill Base On File Path
- Service Stop Commands
- Service Stop Commands (PowerShell)
- Service Stop Commands (Sysmon)
- Service Stop Commands (Windows Event Log)
- Suspicious wevtutil Usage
- Unload Sysmon Filter Driver
- Unloading AMSI via Reflection
- WFP Blocked Connection from EDR Agent (Windows Event Log)
- WFP Filter and Provider Changed (Windows Event Log)
- Windows - Service Stop (PowerShell)
- Windows - Service Stop (Windows Event Log)
- Windows AD Domain Controller Audit Policy Disabled
- Windows AD GPO Deleted
- Windows AD GPO Disabled
- Windows Attempt To Stop Security Service
- Windows Audit Policy Auditing Option Disabled via Auditpol
- Windows Audit Policy Cleared via Auditpol
- Windows Audit Policy Disabled via Auditpol
- Windows Audit Policy Disabled via Legacy Auditpol
- Windows Audit Policy Excluded Category via Auditpol
- Windows Audit Policy Restored via Auditpol
- Windows Audit Policy Security Descriptor Tampering via Auditpol
- Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc
- Windows Cisco Secure Endpoint Unblock File Via Sfc
- Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc
- Windows CrowdStrike Agent Registry Key Removal
- Windows Defender ASR or Threat Configuration Tamper
- Windows Defender Disabled Detection (PowerShell)
- Windows Defender Disabled Detection (Sysmon)
- Windows Defender Disabled Detection (Windows Event Log)
- Windows Defender Exclusion Registry Entry
- Windows Disable or Modify Tools Via Taskkill
- Windows Disable or Stop Browser Process
- Windows Disable Windows Event Logging Disable HTTP Logging
- Windows DisableAntiSpyware Registry
- Windows DISM Remove Defender
- Windows EDRSilencer Execution
- Windows Event For Service Disabled
- Windows Event Log Cleared
- Windows Event Logging Service Has Shutdown
- Windows Eventlog Cleared Via Wevtutil
- Windows Excessive Disabled Services Event
- Windows Filtering Platform Policy Added to Block EDR Process
- Windows Firewall Disabled (PowerShell)
- Windows Firewall Disabled (Sysmon)
- Windows Firewall Disabled (Windows Event Log)
- Windows Firewall Rule Creation (PowerShell)
- Windows Firewall Rule Creation (Sysmon)
- Windows Firewall Rule Creation (Windows Event Log)
- Windows Global Object Access Audit List Cleared Via Auditpol
- Windows Impair Defense Add Xml Applocker Rules
- Windows Impair Defense Change Win Defender Health Check Intervals
- Windows Impair Defense Change Win Defender Quick Scan Interval
- Windows Impair Defense Change Win Defender Throttle Rate
- Windows Impair Defense Change Win Defender Tracing Level
- Windows Impair Defense Configure App Install Control
- Windows Impair Defense Define Win Defender Threat Action
- Windows Impair Defense Delete Win Defender Context Menu
- Windows Impair Defense Delete Win Defender Profile Registry
- Windows Impair Defense Deny Security Software With Applocker
- Windows Impair Defense Disable Controlled Folder Access
- Windows Impair Defense Disable Defender Firewall And Network
- Windows Impair Defense Disable Defender Protocol Recognition
- Windows Impair Defense Disable PUA Protection
- Windows Impair Defense Disable Realtime Signature Delivery
- Windows Impair Defense Disable Web Evaluation
- Windows Impair Defense Disable Win Defender App Guard
- Windows Impair Defense Disable Win Defender Compute File Hashes
- Windows Impair Defense Disable Win Defender Gen reports
- Windows Impair Defense Disable Win Defender Network Protection
- Windows Impair Defense Disable Win Defender Report Infection
- Windows Impair Defense Disable Win Defender Scan On Update
- Windows Impair Defense Disable Win Defender Signature Retirement
- Windows Impair Defense Overide Win Defender Phishing Filter
- Windows Impair Defense Override SmartScreen Prompt
- Windows Impair Defense Set Win Defender Smart Screen Level To Warn
- Windows Impair Defenses Disable Auto Logger Session
- Windows Impair Defenses Disable HVCI
- Windows Impair Defenses Disable Win Defender Auto Logging
- Windows Important Audit Policy Disabled
- Windows Increase in Group or Object Modification Activity
- Windows Increase in User Modification Activity
- Windows MpCmdRun RemoveDefinitions Execution
- Windows New Custom Security Descriptor Set On EventLog Channel
- Windows New EventLog ChannelAccess Registry Value Set
- Windows Outlook Dialogs Disabled from Unusual Process
- Windows PowerShell Disable HTTP Logging
- Windows Powershell Import Applocker Policy
- Windows Raccine Scheduled Task Deletion
- Windows Registry Delete Task SD
- Windows Registry Dotnet ETW Disabled Via ENV Variable
- Windows Terminating Lsass Process
- Wmic NonInteractive App Uninstallation
Kusto 113 rules
- 1Password - Changes to firewall rules
- 1Password - Log Ingestion Failure
- AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
- AWSCloudTrail - Amazon ECR image scanning disabled
- AWSCloudTrail - AWS GuardDuty detector disabled or suspended
- AWSCloudTrail - Changes to Amazon VPC settings
- AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups
- AWSCloudTrail - Changes to AWS Security Group ingress and egress settings
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Config Service Resource Deletion Attempts
- AWSCloudTrail - Network ACL with all the open ports to a specified CIDR
- AWSCloudTrail - Tampering to AWS CloudTrail logs
- Azure DevOps Audit Stream Disabled
- Azure Diagnostic settings removed from a resource
- Check Point Exposure Management - Alert Ingestion Anomaly
- Cisco SE - Policy update failure
- CiscoISE - Log collector was suspended
- Common Event Format (CEF) via AMA - Critical or High Severity Detections by User
- Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed)
- Conditional Access - A Conditional Access policy was deleted
- Conditional Access - A Conditional Access policy was disabled
- Conditional Access - A Conditional Access policy was put into report-only mode
- Conditional Access - A Conditional Access policy was updated
- Conditional Access - A new Conditional Access policy was created
- Copilot - File Uploads Disabled
- Copilot - Plugin Tampering (Enable and Disable Within 5 Minutes)
- CTERA Mass Access Denied Detection Analytic
- Dataverse - Audit logging disabled
- Deleted a Custom Field Mapping profile
- Deleted a Tenant
- Detect Windows Allow Firewall Rule Addition/Modification
- Detect Windows Update Disabled from Registry
- Dev-0270 Malicious Powershell usage
- Disable or Modify Windows Defender
- Disabling Security Services via Registry
- Doppelpaymer Stop Services
- Excessive Denied Proxy Traffic
- Exchange AuditLog Disabled
- Firewall rule manipulation attempts stateful anomaly on database
- GCP Audit Logs - Data Access Logging Exemption Added for Principal
- GCP Audit Logs - Detect Bulk VM Snapshot Deletion
- GCP Audit Logs - Detect Organization Policy Deletion or Updation
- GCP Audit Logs - DNSSEC Disabled on Managed DNS Zone
- GCP Audit Logs - Open Firewall Rule Created or Modified
- GCP Audit Logs - VPC Flow Logs Disabled
- GCP IAM - Disable Data Access Logging
- GCP Security Command Center - Detect DNSSEC disabled for DNS zones
- GCP Security Command Center - Detect Resources with Logging Disabled
- GitHub Two Factor Auth Disable
- Google SecOps - Single-Event Alert
- Illumio Enforcement Change Analytic Rule
- Illumio Firewall Tampering Analytic Rule
- Illumio VEN Clone Detection Rule
- Illumio VEN Deactivated Detection Rule
- Illumio VEN Offline Detection Rule
- Illumio VEN Suspend Detection Rule
- Imminent Ransomware
- McAfee ePO - Agent Handler down
- McAfee ePO - Attempt uninstall McAfee agent
- McAfee ePO - Deployment failed
- McAfee ePO - Error sending alert
- McAfee ePO - File added to exceptions
- McAfee ePO - Firewall disabled
- McAfee ePO - Logging error occurred
- McAfee ePO - Multiple threats on same host
- McAfee ePO - Scanning engine disabled
- McAfee ePO - Task error
- McAfee ePO - Threat was not blocked
- McAfee ePO - Unable to clean or delete infected file
- McAfee ePO - Update failed
- MosaicLoader
- Netskope - Repeated or Critical Policy Violations
- NRT Azure DevOps Audit Stream Disabled
- NRT GitHub Two Factor Auth Disable
- Office Policy Tampering
- Pathlock TDnR - ABAP Source Code Changes
- Pathlock TDnR - Authorization Check Value Changes (SU24)
- Pathlock TDnR - Critical File Integrity Changes
- Pathlock TDnR - DDIC Table Utility Changes (SE14)
- Pathlock TDnR - Generic SAP Change Documents
- Pathlock TDnR - Generic Table Content Changes
- Pathlock TDnR - Global System Change Setting Events
- Pathlock TDnR - ICM Security Events
- Pathlock TDnR - SAP Client Configuration Changes
- Pathlock TDnR - SAP HANA Parameter Changes
- Pathlock TDnR - SAP Instance Profile Changes
- Pathlock TDnR - SAP Security Audit Log Events
- Pathlock TDnR - SE16N Direct Table Change Documents
- Pathlock TDnR - SU24 Table USOBT_C Changes
- Pathlock TDnR - SU24 Table USOBX_C Changes
- Pathlock TDnR - Switchable Authorization Design Changes
- Pathlock TDnR - Switchable Authorization Runtime Changes
- Pathlock TDnR - System Security Policy Changes
- Pathlock TDnR - Table Parameter Setting Changes
- Pathlock TDnR - User Authorization Buffer Manipulation
- Power Automate - Unusual bulk deletion of flow resources
- SAP BTP - Audit log service unavailable
- SAP BTP - Unaudited custom app with login-only activity
- Scheduled Task Hide
- Security Service Registry ACL Modification
- Starting or Stopping HealthService to Avoid Detection
- Stopping multiple processes using taskkill
- Tailscale Premium: Posture integration disabled or removed
- Trend Micro CAS - Threat detected and not blocked
- UniFi Site Manager: Data Connector Health
- UniFi Site Manager: IPS signature count dropped >50%
- UniFi Site Manager: IPS/IDS disabled or misconfigured
- UniFi Site Manager: System log shipping disabled
- Vaikora - Engine offline
- Valimail Enforce - DMARC Policy Weakened to None
- Valimail Enforce - Email Authentication Key Deleted
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions
- Zero Networks Segement - Machine Removed from protection
YARA-L 37 rules
- AWS Account Leaving Or Removed From The Organization
- AWS CloudTrail Logging Tampered
- AWS Config Service Modified
- AWS Delete CloudWatch Log Group
- AWS Delete VPC Flow Logs
- AWS GuardDuty Disabled
- AWS GuardDuty Publishing Destination Deleted
- AWS GuardDuty Trusted Or Threat IP Lists Tampered
- AWS IAM Access Analyzer Deleted
- AWS S3 Bucket Made Public By ACL
- AWS S3 Public Access Block Removed
- AWS Security Group Open To The World
- GCP BigQuery Datasets Opened To Public
- GCP Cloud Audit Logging Removed From All Services
- GCP Exempt Principals From Audit Log
- GCP Firewall Rule Opened To The World
- GCP Security Command Center Service Disabled
- GCP Storage Bucket Opened To Public
- GitHub Dependabot Vulnerability Alerts Disabled
- GitHub Enterprise Audit Log Stream Destroyed
- GitHub Enterprise Audit Log Stream Modified
- GitHub Personal Access Token Auto Approve Policy Modified
- GitHub Repository Branch Protection Rules Disabled
- GitHub Secret Scanning Disabled Or Bypassed
- GitHub SSO Configuration Modified
- GitHub Two-Factor Authentication Requirement Disabled
- Google Workspace Marketplace Allowlist Configuration
- Google Workspace New Trusted Domain Added
- Office 365 logging has been enabled
- Office 365 logging is disabled
- Reg Add Suspicious Paths
- sap deactivation of security audit log
- sap hanadb audit trail policy changes
- sap hanadb deactivation of audit trail
- sap security audit log configuration change
- sap system or client configuration change
- Windows Event Log Cleared
Panther 99 rules
- A User from the company domain(s) Logged in without SAML
- Account Security Configuration Changed
- Anthropic IP Restriction Deleted
- Anthropic MCP Server Deleted
- Anthropic Organization Settings Updated
- Anthropic SSO Disabled
- AppOmni Alert Passthrough
- Auth0 Attack Protection Monitoring Disabled
- Auth0 Bot Detection Policy Disabled
- AWS ACM Secure Algorithms
- AWS Bedrock Guardrail Updated or Deleted
- AWS CloudTrail Attempt To Leave Org
- AWS CloudTrail CloudWatch Logs
- AWS CloudTrail Least Privilege Access
- AWS CloudTrail Log Validation
- AWS CloudTrail Management Events Enabled
- AWS CloudTrail Retention Lifecycle Too Short
- AWS Config Service Disabled
- AWS DNS Logs Deleted
- AWS EC2 Instance Detailed Monitoring
- AWS EC2 Manual Security Group Change
- AWS GuardDuty Enabled
- AWS GuardDuty Master Account
- AWS Macie Disabled/Updated
- AWS RDS Activity Stream Stopped
- AWS RDS Deletion Protection Disabled
- AWS Redshift Cluster Logging
- AWS S3 Bucket Logging
- AWS S3 Security Control Disabling
- AWS S3 Security Controls Disabled
- AWS SecurityHub Finding Evasion
- AWS Trusted IPSet Modified
- AWS VPC Flow Logs
- AWS VPC Flow Logs Removed
- AWS WAF Logging Configured
- Azure Action Groups Deleted
- Azure Alert Rules Deleted
- Azure Alert Suppression Rule Created or Modified
- Azure Diagnostic Settings Deleted
- Azure Event Hub Deleted
- Azure Log Analytics Workspace Deleted
- Azure Network Watcher Deleted
- Azure Recovery Services Protection Container Deleted
- Azure Resource Lock Deleted
- Azure Storage Immutability Policy Deleted
- Carbon Black Data Forwarder Stopped
- CloudTrail Event Selectors Disabled
- CloudTrail Stopped
- Crowdstrike Systemlog Tampering
- Databricks Delta Sharing Recipient Without IP ACLs
- Databricks High Priority Configuration Changes
- Databricks Verbose Audit Logging Disabled
- Detection content has been deleted from Panther
- EC2 Network ACL Modified
- EC2 Network Gateway Modified
- EC2 Security Group Modified
- EC2 VPC Modified
- GCP Cloud Storage Buckets Modified Or Deleted
- GCP KMS Key Granted to GCS Service Account
- GCP KMS Key Version Disabled or Destroyed
- GitHub Advanced Security Change WITHOUT Repo Archived
- GitHub Repository Ruleset Modified
- GitHub Security Change, includes GitHub Advanced Security
- GSuite User Advanced Protection Change
- Kubernetes Pod Using Host IPC Namespace
- Kubernetes Role With Node Proxy Permissions Created
- MacOS ALF is misconfigured
- MongoDB logging toggled
- MongoDB security alerts disabled or deleted
- OpenAI IP Allowlist Configuration Changes
- OpenAI SCIM Configuration Change
- OSQuery Reports Application Firewall Disabled
- Panther SAML configuration has been modified
- S3 Bucket Encryption Deleted
- S3 Bucket Logging Disabled
- S3 Bucket Replication Deleted
- S3 Bucket Versioning Suspended
- S3 MFA Delete Disabled
- S3 Public Access Block Deleted
- Sensitive API Calls Via VPC Endpoint
- Slack DLP Modified
- Slack EKM Config Changed
- Slack Information Barrier Modified
- Slack Legal Hold Policy Modified
- Slack Microsoft Intune Mobile Device Management Disabled
- Sublime Mailbox Deactivated
- Sublime Message Source Deleted Or Deactivated
- Sublime Rules Deleted Or Deactivated
- Upwind Posture Detection Passthrough
- Wiz CICD Scan Policy Updated Or Deleted
- Wiz Connector Updated Or Deleted
- Wiz Data Classifier Updated Or Deleted
- Wiz Image Integrity Validator Updated Or Deleted
- Wiz Integration Updated Or Deleted
- Wiz Rule Change
- Wiz Update Scanner Settings
- ZIA Backup Deleted
- ZIA Golden Restore Point Dropped
- ZIA Log Streaming Disabled