1200KM / simulation
T1685 Disable or Modify Tools — Attack Simulation
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also…
Technique description
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Disable OpenDNS Umbrella
Procedure 07f43b33-1e15-4e99-be70-bc094157c849; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- ESXi - Disable Account Lockout Policy via PowerCLI
Procedure 091a6290-cd29-41cb-81ea-b12f133c66cb; elevation required; cleanup not declared. Not executed or individually validated.
- Tamper with Windows Defender Evade Scanning -Folder
Procedure 0b19f4ee-de90-4059-88cb-63c800c683ed; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Delete Microsoft Defender ASR Rules - GPO
Procedure 0e7b8a4b-2ca5-4743-a9f9-96051abb6e50; elevation required; cleanup not declared. Not executed or individually validated.
- Disable .NET Event Tracing for Windows Via Environment Variable HKLM Registry - Cmd
Procedure 110b4281-43fe-405f-a184-5d8eaf228ebf; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Block Cybersecurity communication by leveraging Windows Name Resolution Policy Table
Procedure 1174b5df-2c33-490f-8854-f5eb80c907ca; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- AWS - GuardDuty Suspension or Deletion
Procedure 11e65d8d-e7e4-470e-a3ff-82bc56ad938e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable journal logging via sed utility
Procedure 12e5551c-8d5c-408e-b3e4-63f53b03379f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- AMSI Bypass - Remove AMSI Provider Reg Key
Procedure 13f09b91-c953-438e-845b-b585e51cac9b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- AMSI Bypass - Override AMSI via COM
Procedure 17538258-5699-4ff1-92d1-5ac9b0dc21f5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable .NET Event Tracing for Windows Via Registry (powershell)
Procedure 19c07a45-452d-4620-90ed-4c34fffbe758; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender Registry
Procedure 1b3e0146-a1e5-4c5c-89fb-1bb2ffe8fc45; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable EventLog-Application ETW Provider Via Registry - Cmd
Procedure 1cac9b54-810e-495c-8aac-989e0076583b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender Registry - Reg.exe
Procedure 1f6743da-6ecc-4a93-b03f-dc357e4b313f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Auditing Configuration Changes on Linux Host
Procedure 212cfbcf-4770-4980-bc21-303e37abd0e3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Clear History
Procedure 23b88394-091b-4968-a42d-fb8076992443; elevation required; cleanup not declared. Not executed or individually validated.
- Kill antimalware protected processes using Backstab
Procedure 24a12b91-05a7-4deb-8d7f-035fa98591bc; elevation required; cleanup not declared. Not executed or individually validated.
- Disable macOS Gatekeeper
Procedure 2a821573-fb3f-4e71-92c3-daac7432f053; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender Evade Scanning -Extension
Procedure 315f4be6-2240-4552-b3e1-d1047f5eecea; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Remove Windows Defender Definition Files
Procedure 3d47daaa-2f56-43e0-94cc-caf5d8d52a68; elevation required; cleanup not declared. Not executed or individually validated.
- Tamper with Defender ATP on Linux/MacOS
Procedure 40074085-dbc8-492b-90a3-11bcfc52fda8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows Disable LSA Protection
Procedure 40075d5f-3a70-4c66-9125-f72bee87247d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Delete Windows Defender Scheduled Tasks
Procedure 4b841aa1-0d05-4b32-bbe7-7564346e7c76; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable syslog
Procedure 4ce786f8-e601-44b5-bfae-9ebb15a7d1c8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable .NET Event Tracing for Windows Via Environment Variable HKLM Registry - PowerShell
Procedure 4d61779d-be7f-425c-b560-0cafb2522911; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- WMIC Tamper with Windows Defender Evade Scanning Folder
Procedure 59d386fc-3a4b-41b8-850d-9e3eee24dfe4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Lockbit Black - Use Registry Editor to turn on automatic logon -Powershell
Procedure 5e27f36d-5132-4537-b43b-413b0d5eec9a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable LittleSnitch
Procedure 62155dd8-bb3d-4f32-b31c-6532ff3ac6a3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable EventLog-Application Auto Logger Session Via Registry - Cmd
Procedure 653c6e17-14a2-4849-851d-f1c0cc8ea9ab; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- AMSI Bypass - AMSI InitFailed
Procedure 695eed40-e949-40e5-b306-b4031e4154bd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- LockBit Black - Disable the ETW Provider of Windows Defender -Powershell
Procedure 69fc085b-5444-4879-8002-b24c8e1a3e02; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Logging Configuration Changes on FreeBSD Host
Procedure 6b8ca3ab-5980-4321-80c3-bcd77c8daed8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender ATP PowerShell
Procedure 6b8df440-51ec-4d53-bf83-899591c9b5d7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Reboot Linux Host via Kernel System Request
Procedure 6d6d3154-1a52-4d1a-9d51-92ab8148b32e; elevation required; cleanup not declared. Not executed or individually validated.
- Disable Powershell ETW Provider - Windows
Procedure 6f118276-121d-4c09-bb58-a8fb4a72ee84; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Microsoft Office Security Features
Procedure 6f5fb61b-4e56-4a3d-a8c3-82e13686c6d7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Hypervisor-Enforced Code Integrity (HVCI)
Procedure 70bd71e6-eba4-4e00-92f7-617911dbe020; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- AMSI Bypass - Create AMSIEnable Reg Key
Procedure 728eca7b-0444-4f6f-ac36-437e3d751dc0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Kill the event log services for stealth
Procedure 7869d7a3-3a30-4d2c-a5d2-f1cd9c34ce66; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Logging Configuration Changes on Linux Host
Procedure 7d40bc58-94c7-4fbb-88d9-ebce9fcdb60c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Throttle Cybersecurity Agent Network Traffic via QoS Policy
Procedure 7dd05b3e-0803-4852-9345-c494eb3e40fe; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Unload Sysmon Filter Driver
Procedure 811b3e76-c41b-430c-ac0d-e2380bfaa164; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Defender Using NirSoft AdvancedRun
Procedure 81ce22fd-9612-4154-918e-8a1f285d214d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Stop Crowdstrike Falcon on Linux
Procedure 828a1278-81cc-4802-96ab-188bf29ca77d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Windows Defender with DISM
Procedure 871438ac-7d6e-432a-b27d-3e7db69faf58; elevation required; cleanup not declared. Not executed or individually validated.
- Disable .NET Event Tracing for Windows Via Registry (cmd)
Procedure 8a4c33be-a0d3-434a-bee6-315405edbd5b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable EventLog-Application ETW Provider Via Registry - PowerShell
Procedure 8f907648-1ebf-4276-b0f0-e2678ca474f0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Carbon Black Response
Procedure 8fba7766-2d11-4b4a-979a-1e3d9cc9a88c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Suspend History
Procedure 94f6a1c9-aae7-46a4-9083-2bb1f5768ec4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LockBit Black - Use Registry Editor to turn on automatic logon -cmd
Procedure 9719d0e1-4fe0-4b2e-9a72-7ad3ee8ddc70; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Arbitrary Security Windows Service
Procedure a1230893-56ac-4c81-b644-2108e982f8f5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender Evade Scanning -Process
Procedure a123ce6a-3916-45d6-ba9c-7d4081315c27; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Uninstall Sysmon
Procedure a316fb2e-5344-470d-91c1-23e15c374edc; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender Registry - Powershell
Procedure a72cfef8-d252-48b3-b292-635d332625c3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender Command Prompt
Procedure aa875ed4-8935-47e2-b2c5-6ec00ab220d2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable ASLR Via sysctl parameters - Linux
Procedure ac333fe1-ce2b-400b-a117-538634427439; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Stop and Remove Arbitrary Security Windows Service
Procedure ae753dda-0f15-4af6-a168-b9ba16143143; elevation required; cleanup not declared. Not executed or individually validated.
- Disable Cb Response
Procedure ae8943f7-0f8d-44de-962d-fbc2e2f03eb8; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Uninstall Crowdstrike Falcon on Windows
Procedure b32b1ccf-f7c1-49bc-9ddd-7d7466a7b297; elevation required; cleanup not declared. Not executed or individually validated.
- Stop and unload Crowdstrike Falcon on macOS
Procedure b3e7510c-2d4c-4249-a33f-591a2bc83eef; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable .NET Event Tracing for Windows Via Environment Variable HKCU Registry - PowerShell
Procedure b42c1f8c-399b-47ae-8fd8-763181395fee; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable journal logging via systemctl utility
Procedure c3a377f9-1203-4454-aa35-9d391d34768f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tamper with Windows Defender ATP using Aliases - PowerShell
Procedure c531aa6e-9c97-4b29-afee-9b7be6fc8a64; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Freeze PPL-protected process with EDR-Freeze
Procedure cbb2573a-a6ad-4c87-aef8-6e175598559b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Auditing Configuration Changes on FreeBSD Host
Procedure cedaf7e7-28ee-42ab-ba13-456abd35d1bd; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LockBit Black - Disable Privacy Settings Experience Using Registry -cmd
Procedure d6d22332-d07d-498f-aea0-6139ecb7850e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LockBit Black - Disable Privacy Settings Experience Using Registry -Powershell
Procedure d8c57eaa-497a-4a08-961e-bd5efd7c9374; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable EventLog-Application Auto Logger Session Via Registry - PowerShell
Procedure da86f239-9bd3-4e85-92ed-4a94ef111a1c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable syslog (freebsd)
Procedure db9de996-441e-4ae0-947b-61b6871e2fdf; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Memory Swap
Procedure e74e4c63-6fde-4ad2-9ee8-21c3a1733114; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Delete Microsoft Defender ASR Rules - InTune
Procedure eea0a6c2-84e9-4e8c-a242-ac585d28d0d1; elevation required; cleanup not declared. Not executed or individually validated.
- Disable Windows Defender with PwSh Disable-WindowsOptionalFeature
Procedure f542ffd3-37b4-4528-837f-682874faa012; elevation required; cleanup not declared. Not executed or individually validated.
- LockBit Black - Disable the ETW Provider of Windows Defender -cmd
Procedure f6df0b8e-2c83-44c7-ba5e-0fa4386bec41; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Clear Pagging Cache
Procedure f790927b-ea85-4a16-b7b2-7eb44176a510; elevation required; cleanup not declared. Not executed or individually validated.
- Disable SELinux
Procedure fc225f36-9279-4c39-b3f9-5141ab74f8d8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable .NET Event Tracing for Windows Via Environment Variable HKCU Registry - Cmd
Procedure fdac1f79-b833-4bab-b4a1-11b1ed676a4b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AMSI Bypass - Patching AmsiScanBuffer
Procedure ff543dd9-4537-458c-b297-c85ae1939e34; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Putter Panda · G0024
- Lazarus Group · G0032
- FIN6 · G0037
- Gamaredon Group · G0047
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Gorgon Group · G0078
- APT38 · G0082
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Rocke · G0106
- Indrik Spider · G0119
- TeamTNT · G0139
- Aquatic Panda · G0143
- Scattered Spider · G1015
- TA2541 · G1018
- APT5 · G1023
- Akira · G1024
- Agrius · G1030
- Saint Bear · G1031
- INC Ransom · G1032
- Play · G1040
- BlackByte · G1043
- Velvet Ant · G1047
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.