32
Groups Using This
1
Tactics
7
Platforms
34
Prevalence Rank
Description

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments. In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing for Windows (ETW), modifying event log configurations (e.g., redirecting Security logs), or interfering with logging pipelines and forwarding mechanisms (e.g., SIEM ingestion). More advanced techniques include leveraging legitimate drivers or debugging mechanisms to render tools non-functional, bypassing anti-tampering protections, and targeting specific defenses such as Sysmon or cloud monitoring agents. Adversaries may also disrupt broader defensive operations, including update mechanisms, logging infrastructure (e.g., syslog), or event aggregation, further degrading an organization’s ability to detect and respond to malicious activity.

View MITRE record ↗

Platforms
ContainersESXiIaaSLinuxmacOSNetwork DevicesWindows
Groups Using T1685 (32)
G0094
Kimsuky
🇷🇺 Russia130 techniques19 software
G0032
Lazarus Group
🇰🇵 North Korea93 techniques26 software
G0096
APT41
🇨🇳 China82 techniques32 software
G0059
Magic Hound
🇮🇷 Iran78 techniques13 software
G0047
Gamaredon Group
🇷🇺 Russia70 techniques6 software
G0010
Turla
🇷🇺 Russia68 techniques30 software
G0069
MuddyWater
🇮🇷 Iran68 techniques21 software
G1015
Scattered Spider
64 techniques9 software
G0102
Wizard Spider
🇷🇺 Russia64 techniques22 software
G1051
Medusa Group
57 techniques5 software
G0082
APT38
🇰🇵 North Korea56 techniques6 software
G0139
TeamTNT
56 techniques4 software
G1052
Contagious Interview
🇰🇵 North Korea54 techniques4 software
G1048
UNC3886
🇨🇳 China49 techniques8 software
G1043
BlackByte
48 techniques8 software
G1054
MirrorFace
🇨🇳 China43 techniques16 software
G0060
BRONZE BUTLER
🇨🇳 China40 techniques14 software
G0037
FIN6
40 techniques12 software
G0106
Rocke
🇨🇳 China36 techniques0 software
G0143
Aquatic Panda
🇨🇳 China35 techniques6 software
G0092
TA505
34 techniques16 software
G0119
Indrik Spider
🇷🇺 Russia33 techniques8 software
G1023
APT5
🇨🇳 China29 techniques13 software
G1018
TA2541
28 techniques9 software
G1040
Play
26 techniques9 software
G1032
INC Ransom
25 techniques8 software
G1047
Velvet Ant
22 techniques2 software
G1030
Agrius
🇮🇷 Iran22 techniques9 software
G1031
Saint Bear
🇷🇺 Russia18 techniques2 software
G1024
Akira
17 techniques8 software
G0078
Gorgon Group
🇷🇺 Russia16 techniques4 software
G0024
Putter Panda
🇨🇳 China4 techniques4 software
↑