Downgrade Attack T1689

Tactic: Defense Impairment

Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of a system’s backward compatibility to force it into less secure modes of operation.

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 7 rules share fields, values, and exclusions.

Fields filtered most (12 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Details3contains 1, eq 1, in 10x00000000, 0, 0x00000001, 0x00000002
TargetObject3ends_with 1, in 1, wildcard 1*components\\pendingxmlidentifier, *poqexeccmdline, \registry\machine\system\*controlset*\control\terminal..., \system\currentcontrolset\control\lsa\lmcompatibilitylevel, hklm\system\controlset*\control\terminal...
EventType2ne 2deletion
host.os.type2eq 2
registry_value_name2eq 2LmCompatibilityLevel, userauthentication
CommandLine1contains 1 add , \control\lsa, controlset
EventID1in 112, 13, 14
Image1ends_with 1\powershell.exe, \pwsh.exe, \reg.exe
OriginalFileName1eq 1powershell.exe, pwsh.dll, reg.exe
RegName1eq 1allowinsecureguestauth
RegValue1eq 11
http.version1is_not_null 1

Top indicator values (39 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypene
deletion
286
CommandLinecontains
add
115
CommandLinecontains
\control\lsa
12
CommandLinecontains
controlset
13
CommandLinecontains
ispplautoenabled
1
CommandLinecontains
new-itemproperty
17
CommandLinecontains
runasppl
1
CommandLinecontains
runaspplboot
1
CommandLinecontains
set-itemproperty
17
Detailscontains
0x00000000
1
Detailscontains
0x00000001
14
Detailscontains
0x00000002
1
Detailseq
0
118
Detailseq
0x00000000
141
Detailsin
0
17
Detailsin
0x00000000
16
Detailsin
0x00000001
14
Detailsin
0x00000002
1
Detailsin
1
14
Detailsin
2
12
EventIDin
12
1
EventIDin
13
1
EventIDin
14
1
Imageends_with
\powershell.exe
1179
Imageends_with
\pwsh.exe
1165
Imageends_with
\reg.exe
158
OriginalFileNameeq
powershell.exe
1138
OriginalFileNameeq
pwsh.dll
1112
OriginalFileNameeq
reg.exe
143
RegNameeq
allowinsecureguestauth
1

Exclusions (1 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
ProcessPathcontains
:\\windows\\winsxs\\
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 3 rules

Splunk 1 rule