1200KM / detection
T1685 Disable or Modify Tools — Detection Rules
Detection workspace for T1685 Disable or Modify Tools: 156 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bitbucket Global Secret Scanning Rule Deleted · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Basic\" log level is required to receive these audit events."}
- Bitbucket Global SSH Settings Changed · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- Bitbucket Audit Log Configuration Updated · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Basic\" log level is required to receive these audit events."}
- Bitbucket Project Secret Scanning Allowlist Added · test · low · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Basic\" log level is required to receive these audit events."}
- Bitbucket Secret Scanning Exempt Repository Added · test · high · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Basic\" log level is required to receive these audit events."}
- Bitbucket Secret Scanning Rule Deleted · test · low · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Basic\" log level is required to receive these audit events."}
- Github Push Protection Bypass Detected · test · low · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- Github Push Protection Disabled · test · high · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- Github Secret Scanning Feature Disabled · test · high · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- AWS GuardDuty Detector Deleted Or Updated · experimental · high · {"product":"aws","service":"cloudtrail"}
- AWS GuardDuty Important Change · test · high · {"product":"aws","service":"cloudtrail"}
- AWS SecurityHub Findings Evasion · stable · high · {"product":"aws","service":"cloudtrail"}
- Azure Kubernetes Events Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Google Cloud Firewall Modified or Deleted · test · medium · {"product":"gcp","service":"gcp.audit"}
- Okta User Session Start Via An Anonymising Proxy Service · test · high · {"product":"okta","service":"okta"}
- ASLR Disabled Via Sysctl or Direct Syscall - Linux · experimental · high · {"product":"linux","service":"auditd"}
- Auditing Configuration Changes on Linux Host · test · high · {"product":"linux","service":"auditd"}
- Logging Configuration Changes on Linux Host · test · high · {"product":"linux","service":"auditd"}
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux · experimental · high · {"product":"linux","category":"process_creation"}
- ESXi Syslog Configuration Change Via ESXCLI · test · medium · {"category":"process_creation","product":"linux"}
- Disable Or Stop Services · test · medium · {"category":"process_creation","product":"linux"}
- Disable Security Tools · test · medium · {"category":"process_creation","product":"macos"}
- Cisco Disabling Logging · test · high · {"product":"cisco","service":"aaa"}
- Cisco Dot1x Disabled · experimental · medium · {"product":"cisco","service":"aaa"}
- FortiGate - Firewall Address Object Added · experimental · medium · {"product":"fortigate","service":"event"}
- FortiGate - New Firewall Policy Added · experimental · medium · {"product":"fortigate","service":"event"}
- Microsoft Malware Protection Engine Crash · test · high · {"product":"windows","service":"application"}
- Microsoft Malware Protection Engine Crash - WER · test · high · {"product":"windows","service":"application"}
- Windows Filtering Platform Blocked Connection From EDR Agent Binary · test · high · {"product":"windows","service":"security","definition":"Requirements: Audit Filtering Platform Connection needs to be enabled"}
- Weak Encryption Enabled and Kerberoast · test · high · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : Account Management > Audit User Account Management, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\Account Management\\Audit User Account Management"}
- ETW Logging Disabled In .NET Processes - Registry · test · high · {"product":"windows","service":"security"}
- HackTool - EDRSilencer Execution - Filter Added · test · high · {"product":"windows","service":"security","definition":"Requirements: Audit Filtering Platform Policy Change needs to be enabled"}
- NetNTLM Downgrade Attack · test · high · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : Object Access > Audit Registry (Success)"}
- Potential Privileged System Service Operation - SeLoadDriverPrivilege · test · medium · {"product":"windows","service":"security"}
- Windows Defender Exclusion List Modified · test · medium · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : Security Settings/Local Policies/Audit Policy, Registry System Access Control (SACL): Auditing/User"}
- Windows Defender Exclusion Registry Key - Write Access Requested · test · medium · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : Security Settings/Local Policies/Audit Policy, Registry System Access Control (SACL): Auditing/User"}
- Sysmon Application Crashed · test · high · {"product":"windows","service":"system"}
- Windows Defender Threat Detection Service Disabled · stable · medium · {"product":"windows","service":"system"}
- Windows Defender Grace Period Expired · stable · high · {"product":"windows","service":"windefend"}
- Windows Defender Exclusions Added · stable · medium · {"product":"windows","service":"windefend"}
- Windows Defender Exploit Guard Tamper · test · high · {"product":"windows","service":"windefend"}
- Windows Defender Submit Sample Feature Disabled · stable · low · {"product":"windows","service":"windefend"}
- Windows Defender Malware And PUA Scanning Disabled · stable · high · {"product":"windows","service":"windefend"}
- Windows Defender Real-time Protection Disabled · stable · high · {"product":"windows","service":"windefend"}
- Windows Defender Real-Time Protection Failure/Restart · stable · medium · {"product":"windows","service":"windefend"}
- Win Defender Restored Quarantine File · test · high · {"product":"windows","service":"windefend"}
- Windows Defender Configuration Changes · stable · high · {"product":"windows","service":"windefend"}
- Microsoft Defender Tamper Protection Trigger · stable · high · {"product":"windows","service":"windefend"}
- Windows Defender Virus Scanning Feature Disabled · stable · high · {"product":"windows","service":"windefend"}
- Suspicious PROCEXP152.sys File Created In TMP · test · medium · {"product":"windows","category":"file_event"}
- Load Of RstrtMgr.DLL By A Suspicious Process · test · high · {"category":"image_load","product":"windows"}
- Load Of RstrtMgr.DLL By An Uncommon Process · test · low · {"category":"image_load","product":"windows"}
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location · experimental · high · {"category":"image_load","product":"windows"}
- Tamper Windows Defender - PSClassic · test · high · {"product":"windows","category":"ps_classic_provider_start"}
- AMSI Bypass Pattern Assembly GetType · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential AMSI Bypass Script Using NULL Bits · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Disable-WindowsOptionalFeature Command PowerShell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Disable of ETW Trace - Powershell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Tamper Windows Defender - ScriptBlockLogging · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Windows Defender Exclusions Added - PowerShell · test · medium · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - CobaltStrike BOF Injection Pattern · test · high · {"category":"process_access","product":"windows"}
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs · experimental · high · {"category":"process_access","product":"windows"}
- Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze · experimental · high · {"category":"process_access","product":"windows","definition":"Requires Sysmon Event ID 10 (ProcessAccess) with CallTrace enabled.\nExample sysmon config snippet with grouping, as logging individual ProcessAccess events can generate excessive logs:\n<ProcessAccess onmatch=\"include\">\n <Rule groupRelation=\"and\">\n <TargetImage condition=\"end with\">\\MsMpEng.exe</TargetImage>\n <SourceImage condition=\"end with\">\\WerFaultSecure.exe</SourceImage>\n </Rule>\n</ProcessAccess>\n"}
- Windows AMSI Related Registry Tampering Via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- Windows Credential Guard Registry Tampering Via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction' · experimental · high · {"category":"process_creation","product":"windows"}
- Windows Defender Context Menu Removed · experimental · high · {"category":"process_creation","product":"windows"}
- Devcon Execution Disabling VMware VMCI Device · experimental · high · {"category":"process_creation","product":"windows"}
- Dism Remove Online Package · test · medium · {"category":"process_creation","product":"windows"}
- Filter Driver Unloaded Via Fltmc.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Sysmon Driver Unloaded Via Fltmc.EXE · test · high · {"product":"windows","category":"process_creation"}
- Hacktool - EDR-Freeze Execution · experimental · high · {"category":"process_creation","product":"windows"}
- HackTool - EDRSilencer Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - PowerTool Execution · test · high · {"product":"windows","category":"process_creation"}
- HackTool - Stracciatella Execution · test · high · {"category":"process_creation","product":"windows"}
- Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious Windows Trace ETW Session Tamper Via Logman.EXE · test · high · {"category":"process_creation","product":"windows"}
- Windows Defender Definition Files Removed · test · high · {"category":"process_creation","product":"windows"}
- Potential AMSI Bypass Via .NET Reflection · test · high · {"category":"process_creation","product":"windows"}
- Potential AMSI Bypass Using NULL Bits · test · medium · {"product":"windows","category":"process_creation"}
- Powershell Base64 Encoded MpPreference Cmdlet · test · high · {"category":"process_creation","product":"windows"}
- Powershell Defender Disable Scan Feature · test · high · {"category":"process_creation","product":"windows"}
- Powershell Defender Exclusion · test · medium · {"category":"process_creation","product":"windows"}
- Disable Windows Defender AV Security Monitoring · test · high · {"category":"process_creation","product":"windows"}
- Windows Firewall Disabled via PowerShell · test · medium · {"category":"process_creation","product":"windows"}
- Disabled IE Security Features · test · high · {"category":"process_creation","product":"windows"}
- Obfuscated PowerShell OneLiner Execution · test · high · {"product":"windows","category":"process_creation"}
- Tamper Windows Defender Remove-MpPreference · test · high · {"product":"windows","category":"process_creation"}
- Service StartupType Change Via PowerShell Set-Service · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Uninstall of Windows Defender Feature via PowerShell · experimental · high · {"category":"process_creation","product":"windows"}
- PUA - CleanWipe Execution · test · high · {"category":"process_creation","product":"windows"}
- Add SafeBoot Keys Via Reg Utility · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE · test · medium · {"category":"process_creation","product":"windows"}
- SafeBoot Registry Key Deleted Via Reg.EXE · test · high · {"category":"process_creation","product":"windows"}
- Service Registry Key Deleted Via Reg.EXE · test · high · {"category":"process_creation","product":"windows"}
- Disabling Windows Defender WMI Autologger Session via Reg.exe · experimental · high · {"category":"process_creation","product":"windows"}
- Security Service Disabled Via Reg.EXE · test · high · {"category":"process_creation","product":"windows"}
- Reg Add Suspicious Paths · test · high · {"category":"process_creation","product":"windows"}
- Disabled Volume Snapshots · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Windows Defender Registry Key Tampering Via Reg.EXE · test · high · {"category":"process_creation","product":"windows"}
- Write Protect For Storage Disabled · test · medium · {"product":"windows","category":"process_creation"}
- Python Function Execution Security Warning Disabled In Excel · test · high · {"category":"process_creation","product":"windows"}
- Service StartupType Change Via Sc.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Suspicious Activity Using SeCEdit · test · medium · {"category":"process_creation","product":"windows"}
- Raccine Uninstall · test · high · {"category":"process_creation","product":"windows"}
- ETW Logging Tamper In .NET Processes Via CommandLine · test · high · {"category":"process_creation","product":"windows"}
- ETW Trace Evasion Activity · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Windows Service Tampering · test · high · {"category":"process_creation","product":"windows"}
- Sysinternals PsSuspend Suspicious Execution · test · high · {"category":"process_creation","product":"windows"}
- Sysmon Configuration Update · test · medium · {"category":"process_creation","product":"windows"}
- Uninstall Sysinternals Sysmon · test · high · {"category":"process_creation","product":"windows"}
- Taskkill Symantec Endpoint Protection · test · high · {"category":"process_creation","product":"windows"}
- Uninstall Crowdstrike Falcon Sensor · test · high · {"category":"process_creation","product":"windows"}
- Vulnerable Driver Blocklist Registry Tampering Via CommandLine · experimental · high · {"category":"process_creation","product":"windows"}
- PPL Tampering Via WerFaultSecure · experimental · high · {"category":"process_creation","product":"windows"}
- Potential Windows Defender Tampering Via Wmic.EXE · test · high · {"product":"windows","category":"process_creation"}
- Service Startup Type Change Via Wmic.EXE · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential Tampering With Security Products Via WMIC · test · high · {"category":"process_creation","product":"windows"}
- Windows Credential Guard Related Registry Value Deleted - Registry · experimental · high · {"category":"registry_delete","product":"windows"}
- Folder Removed From Exploit Guard ProtectedFolders List - Registry · test · high · {"category":"registry_delete","product":"windows"}
- Removal Of AMSI Provider Registry Keys · test · high · {"product":"windows","category":"registry_delete"}
- Removal Of Index Value to Hide Schedule Task - Registry · test · medium · {"product":"windows","category":"registry_delete"}
- Removal Of SD Value to Hide Schedule Task - Registry · test · medium · {"product":"windows","category":"registry_delete"}
- Windows Defender Threat Severity Default Action Modified · experimental · high · {"category":"registry_event","product":"windows"}
- NetNTLM Downgrade Attack - Registry · test · high · {"product":"windows","category":"registry_event"}
- Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback · test · medium · {"product":"windows","category":"registry_set"}
- Potential AMSI COM Server Hijacking · test · high · {"category":"registry_set","product":"windows"}
- AMSI Disabled via Registry Modification · experimental · high · {"category":"registry_set","product":"windows"}
- Sysmon Driver Altitude Change · test · high · {"category":"registry_set","product":"windows"}
- Windows Credential Guard Disabled - Registry · experimental · high · {"category":"registry_set","product":"windows"}
- Windows Defender Exclusions Added - Registry · test · medium · {"product":"windows","category":"registry_set"}
- Antivirus Filter Driver Disallowed On Dev Drive - Registry · test · high · {"category":"registry_set","product":"windows"}
- Windows Hypervisor Enforced Code Integrity Disabled · test · high · {"category":"registry_set","product":"windows"}
- Hypervisor Enforced Paging Translation Disabled · test · high · {"category":"registry_set","product":"windows"}
- Disable Privacy Settings Experience in Registry · test · medium · {"category":"registry_set","product":"windows"}
- Windows Defender Service Disabled - Registry · test · high · {"product":"windows","category":"registry_set"}
- Disable Exploit Guard Network Protection on Windows Defender · test · medium · {"category":"registry_set","product":"windows"}
- Disabled Windows Defender Eventlog · test · high · {"category":"registry_set","product":"windows"}
- Disable PUA Protection on Windows Defender · test · high · {"category":"registry_set","product":"windows"}
- Disable Tamper Protection on Windows Defender · test · medium · {"category":"registry_set","product":"windows"}
- ETW Logging Disabled In .NET Processes - Sysmon Registry · test · high · {"product":"windows","category":"registry_set"}
- Scripted Diagnostics Turn Off Check Enabled - Registry · test · medium · {"product":"windows","category":"registry_set"}
- Suspicious Application Allowed Through Exploit Guard · test · high · {"category":"registry_set","product":"windows"}
- Hide Schedule Task Via Index Value Tamper · test · high · {"category":"registry_set","product":"windows"}
- Uncommon Extension In Keyboard Layout IME File Registry Value · test · high · {"product":"windows","category":"registry_set"}
- Suspicious Path In Keyboard Layout IME File Registry Value · test · high · {"product":"windows","category":"registry_set"}
- Microsoft Office Protected View Disabled · test · high · {"product":"windows","category":"registry_set"}
- Python Function Execution Security Warning Disabled In Excel - Registry · test · high · {"category":"registry_set","product":"windows"}
- ETW Logging Disabled For rpcrt4.dll · test · low · {"product":"windows","category":"registry_set"}
- ETW Logging Disabled For SCM · test · low · {"product":"windows","category":"registry_set"}
- Tamper With Sophos AV Registry Keys · test · high · {"category":"registry_set","product":"windows"}
- Suspicious Service Installed · test · medium · {"category":"registry_set","product":"windows"}
- WFP Filter Added via Registry · experimental · medium · {"category":"registry_set","product":"windows"}
- Windows Vulnerable Driver Blocklist Disabled · experimental · high · {"category":"registry_set","product":"windows"}
- Disable Windows Defender Functionalities Via Registry Keys · test · high · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0497 Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
AN1369 Analytic 1369
Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.
AN1370 Analytic 1370
Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.
AN1371 Analytic 1371
Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.
AN1372 Analytic 1372
Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events
AN1373 Analytic 1373
Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.
AN1374 Analytic 1374
Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.
AN2044 Analytic 2044
Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Putter Panda · G0024
- Lazarus Group · G0032
- FIN6 · G0037
- Gamaredon Group · G0047
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Gorgon Group · G0078
- APT38 · G0082
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Rocke · G0106
- Indrik Spider · G0119
- TeamTNT · G0139
- Aquatic Panda · G0143
- Scattered Spider · G1015
- TA2541 · G1018
- APT5 · G1023
- Akira · G1024
- Agrius · G1030
- Saint Bear · G1031
- INC Ransom · G1032
- Play · G1040
- BlackByte · G1043
- Velvet Ant · G1047
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.