Disable or Modify Tools T1685

Tactic: Defense Impairment

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Events covered

76 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 5Process terminated
SysmonEvent ID 7Image loaded
SysmonEvent ID 10ProcessAccess
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 17PipeEvent (Pipe Created)
SysmonEvent ID 18PipeEvent (Pipe Connected)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4670Permissions on an object were changed.
Security-AuditingEvent ID 4673A privileged service was called.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4719System audit policy was changed.
Security-AuditingEvent ID 4720A user account was created.
Security-AuditingEvent ID 4738A user account was changed.
Security-AuditingEvent ID 4950A Windows Firewall setting has changed.
Security-AuditingEvent ID 5123A configuration entry changed in the OCSP Responder Service.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5441The following filter was present when the Windows Filtering Platform Base Filtering Engine started.
Security-AuditingEvent ID 5447A Windows Filtering Platform filter has been changed.
Security-AuditingEvent ID 5448A Windows Filtering Platform provider has been changed.
1Password-Accountaccount-updatfwUpdate Firewall Rules
Application-ErrorEvent ID 1000Faulting application name: Faulting_application_name, version: version, time stamp: 0xFaulting_module_name.
Application-PopupEvent ID 26Application popup: Caption : Message.
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceRegistryEventsanyRegistry activity
Defender-DeviceRegistryEventsRegistryKeyDeletedRegistry key deleted
Defender-DeviceRegistryEventsRegistryValueSetRegistry value set
Defender-DeviceRegistryEventsRegistryValueDeletedRegistry value deleted
Defender-DeviceRegistryEventsRegistryKeyRenamedRegistry key renamed
ESFexecProcess Execution
ESFsignalSignal Delivery
Linux-AuditdEvent ID 1131SERVICE_STOP
Linux-AuditdEvent ID 1200DAEMON_START
Linux-AuditdEvent ID 1201DAEMON_END
Linux-AuditdEvent ID 1202DAEMON_ABORT
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1309EXECVE
MSSQLSERVEREvent ID 33205Event ID 33205
EventlogEvent ID 104The LogFileCleared.Channel log file was cleared.
EventlogEvent ID 1100The event logging service has shut down.
EventlogEvent ID 1102The audit log was cleared.
IIS-ConfigurationEvent ID 29Changes to 'Configuration' at 'ConfigPath' have successfully been committed.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
SMBClientEvent ID 31018Guidance: An administrator has enabled AllowInsecureGuestAuth.
WMI-ActivityEvent ID 5858Id = Operation_ClientFailure.Id; ClientMachine = Operation_ClientFailure.ClientMachine; User = Operation_ClientFailure.User; ClientProcessId = Operation_ClientFailure.ClientProcessId; Component = Operation_ClientFailure.Component; Operation = Operation_ClientFailure.Operation; ResultCode = Operation_ClientFailure.ResultCode; PossibleCause = Operation_ClientFailure.PossibleCause.
Windows-DefenderEvent ID 1009ProductName has restored an item from quarantine.
Windows-DefenderEvent ID 1119ProductName has encountered a critical error when taking action on malware or other potentially unwanted software.
Windows-DefenderEvent ID 3002ProductName Real-Time Protection feature has encountered an error and failed.
Windows-DefenderEvent ID 3007ProductName Real-time Protection feature has restarted.
Windows-DefenderEvent ID 5001Product Name Real-time Protection scanning for malware and other potentially unwanted software was disabled.
Windows-DefenderEvent ID 5007Product Name Configuration has changed.
Windows-DefenderEvent ID 5010ProductName scanning for spyware and other potentially unwanted software is disabled.
Windows-DefenderEvent ID 5012ProductName scanning for viruses is disabled.
Windows-DefenderEvent ID 5013Tamper Protection Changed Type a change to Product Name.
Windows-DefenderEvent ID 5101{Product Name} grace period has expired.
Windows-Firewall-With-Advanced-SecurityEvent ID 2003A Windows Defender Firewall setting in the Profiles profile has changed.
Windows-Firewall-With-Advanced-SecurityEvent ID 2004A rule has been added to the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2005A rule has been modified in the Windows Defender Firewall exception list.
PowerShellEvent ID 600Event ID 600
PowerShellEvent ID 800Event ID 800
Service-Control-ManagerEvent ID 7036The Microsoft Software Shadow Copy Provider service entered the stopped state.
Service-Control-ManagerEvent ID 7040The start type of the msdsm service was changed from boot start to demand start.
Sysmon-for-LinuxEvent ID 1Process Create
Windows-Error-ReportingEvent ID 1001Fault bucket , type.

Authoring guide

These 916 rules share fields, values, and exclusions.

Fields filtered most (441 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType153eq 99, in 41, wildcard 11, ne 5, ends_with 3exec, ProcessRollup2, exec_event, start, deleted
CommandLine139contains 123, in 15, regex_match 5, ends_with 4, match 3, wildcard 3, starts_with 1disabled, add , config, add , delete
Details123eq 89, is_not_null 26, contains 17, in 11, wildcard 4, ends_with 10x00000000, 0x00000001, dword (0x00000000), 0, 1
Image103ends_with 72, eq 12, is_not_null 12, starts_with 11, contains 6, wildcard 3, regex_match 2, is_null 1\powershell.exe, \pwsh.exe, \reg.exe, \powershell_ise.exe, \msmpeng.exe
process_name102eq 82, in 14, starts_with 6, regex_match 4, ends_with 2, is_not_null 2, wildcard 1powershell.exe, auditpol.exe, chkconfig, killall, powershell_ise.exe
data_stream.dataset87eq 87aws.cloudtrail, o365.audit, gcp.audit, okta.system, azure.activitylogs
EventID74eq 69, in 3, regex_match 34104, 4688, 1, 4103, 4656
event.type72eq 66, in 5, ne 1start, change, deletion, process_started, creation
TargetObject70ends_with 30, contains 28, wildcard 14, eq 7, starts_with 2, is_not_null 1\software\microsoft\windows..., \control\keyboard layouts\, \deviceguard\enablevirtualizationbasedsecurity, \deviceguard\lsacfgflags, \microsoft\windows\currentversion\winevt\channels\
event.outcome66eq 65, in 1success, failure
aws::eventName64eq 45, in 22, ne 2deletetrail, stoplogging, updatetrail, PutBucketVersioning, deletedetector
OriginalFileName61eq 58, in 5powershell.exe, pwsh.dll, reg.exe, auditpol.exe, powershell_ise.exe
Provider_Name59eq 55, in 4exchange, ec2.amazonaws.com, cloudtrail.amazonaws.com, bedrock.amazonaws.com, guardduty.amazonaws.com
host.os.type58eq 57, in 1
registry_path56ends_with 34, contains 20, in 3\\microsoft\\windows defender\\spynet, \\policies\\microsoft\\windows defender, *\\microsoft\\windows\\currentversion\\winevt\\channels\\*, *\\microsoft\\windows\\system\\enablesmartscreen, *\\software\\microsoft\\windows\\currentversion\\explorer...

Top indicator values (4438 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
65369
event.typeeq
start
491078
event.typeeq
change
1494
data_stream.dataseteq
aws.cloudtrail
37169
data_stream.dataseteq
o365.audit
1347
data_stream.dataseteq
gcp.audit
1269
Detailseq
0x00000000
2541
Detailseq
0x00000001
2361
Detailseq
dword (0x00000000)
1838
Detailseq
0
1118
EventTypeeq
exec
17576
security_result.actioneq
ALLOW
17102
EventTypein
exec
14201
EventTypein
start
13163
EventTypein
ProcessRollup2
12117
EventTypein
exec_event
12149
Imageends_with
\powershell.exe
14179
Imageends_with
\reg.exe
1358
Imageends_with
\pwsh.exe
12165
OriginalFileNameeq
powershell.exe
14138
OriginalFileNameeq
pwsh.dll
13112
OriginalFileNameeq
reg.exe
1343
OriginalFileNameeq
auditpol.exe
1010
data.typeeq
sapi
1418
process_nameeq
powershell.exe
13184
EventIDeq
4104
11269
event.categoryeq
web
1120
Provider_Nameeq
exchange
1017
aws::eventSourceeq
cloudtrail.amazonaws.com
1010
resultTypein
Succeeded
1051

Exclusions (970 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
9
Imageeq
c:\windows\system32\svchost.exe
6
process.thread.Ext.call_stack_final_user_module.namein
Unknown
6
process.thread.Ext.call_stack_final_user_module.namein
Undetermined
5
user.ideq
s-1-5-18
6
CommandLinecontains
/?
4
aws::userIdentity.typeeq
awsservice
4
Imageends_with
\msmpeng.exe
3
Imagein
*:\\windows\\system32\\*
3
Imagein
*:\\windows\\syswow64\\*
3
Imagein
:\\windows\\winsxs\\*
3
Imagestarts_with
c:\programdata\microsoft\windows defender\platform\
3
Imagestarts_with
c:\windows\winsxs\
3
aws::errorCodeeq
accessdenied
3
aws::userAgenteq
aws internal
3

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 262 rules

Elastic 217 rules

Splunk 188 rules

Kusto 113 rules

YARA-L 37 rules

Panther 99 rules