Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1685

T1685Disable or Modify Tools

T1685 — Disable or Modify Tools is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 119 detection use cases covering it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
119Use cases
0Articles
6Sub-techniques
1Tactic

Sub-techniques (6)

Use cases covering this technique (119)

Cisco ASA - Core Syslog Message Volume Drop ESCU actions · hunting P Cisco ASA - Logging Disabled via CLI ESCU actions · alerting P Cisco ASA - Logging Filters Configuration Tampering ESCU actions · hunting P ESXi Download Errors ESCU actions · hunting P ESXi Encryption Settings Modified ESCU actions · alerting P ESXi Lockdown Mode Disabled ESCU actions · alerting P ESXi Loghost Config Tampering ESCU actions · alerting P ESXi VIB Acceptance Level Tampering ESCU actions · alerting P M365 Copilot Agentic Jailbreak Attack ESCU actions · hunting P M365 Copilot Impersonation Jailbreak Attack ESCU actions · alerting P M365 Copilot Information Extraction Jailbreak Attack ESCU actions · alerting P M365 Copilot Jailbreak Attempts ESCU actions · hunting P M365 Copilot Non Compliant Devices Accessing M365 Copilot ESCU actions · hunting P Azure AD Block User Consent For Risky Apps Disabled ESCU actions · alerting P GitHub Enterprise Delete Branch Ruleset ESCU actions · hunting P GitHub Enterprise Disable 2FA Requirement ESCU actions · hunting P GitHub Enterprise Disable Classic Branch Protection Rule ESCU actions · hunting P GitHub Enterprise Disable Dependabot ESCU actions · hunting P GitHub Enterprise Disable IP Allow List ESCU actions · hunting P GitHub Enterprise Register Self Hosted Runner ESCU actions · hunting P GitHub Organizations Delete Branch Ruleset ESCU actions · hunting P GitHub Organizations Disable 2FA Requirement ESCU actions · hunting P GitHub Organizations Disable Classic Branch Protection Rule ESCU actions · hunting P GitHub Organizations Disable Dependabot ESCU actions · hunting P Microsoft Intune DeviceManagementConfigurationPolicies ESCU actions · hunting P O365 Block User Consent For Risky Apps Disabled ESCU actions · alerting P Add or Set Windows Defender Exclusion ESCU actions · alerting P Disable AMSI Through Registry ESCU actions · alerting P Disable Defender AntiVirus Registry ESCU actions · alerting P Disable Defender BlockAtFirstSeen Feature ESCU actions · alerting P Disable Defender Enhanced Notification ESCU actions · alerting P Disable Defender MpEngine Registry ESCU actions · alerting P Disable Defender Spynet Reporting ESCU actions · alerting P Disable Defender Submit Samples Consent Feature ESCU actions · alerting P Disable ETW Through Registry ESCU actions · alerting P Disable Registry Tool ESCU actions · alerting P Disable Schedule Task ESCU actions · hunting P Disable Show Hidden Files ESCU actions · hunting P Disable Windows App Hotkeys ESCU actions · alerting P Disable Windows Behavior Monitoring ESCU actions · alerting P Disable Windows SmartScreen Protection ESCU actions · alerting P Disabling CMD Application ESCU actions · alerting P Disabling ControlPanel ESCU actions · alerting P Disabling Defender Services ESCU actions · alerting P Disabling Firewall with Netsh ESCU actions · hunting P Disabling FolderOptions Windows Feature ESCU actions · alerting P Disabling NoRun Windows App ESCU actions · alerting P Disabling Task Manager ESCU actions · alerting P ETW Registry Disabled ESCU actions · alerting P Excessive number of service control start as disabled ESCU actions · hunting P Excessive Usage Of Taskkill ESCU actions · hunting P Hide User Account From Sign-In Screen ESCU actions · alerting P Linux Impair Defenses Process Kill ESCU actions · hunting P Powershell Disable Security Monitoring ESCU actions · alerting P Powershell Remove Windows Defender Directory ESCU actions · alerting P Powershell Windows Defender Exclusion Commands ESCU actions · alerting P Process Kill Base On File Path ESCU actions · alerting P Unload Sysmon Filter Driver ESCU actions · alerting P Unloading AMSI via Reflection ESCU actions · alerting P Windows AD Domain Controller Audit Policy Disabled ESCU actions · alerting P Windows AD GPO Deleted ESCU actions · alerting P Windows AD GPO Disabled ESCU actions · alerting P Windows Attempt To Stop Security Service ESCU actions · alerting P Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc ESCU actions · hunting P Windows Cisco Secure Endpoint Unblock File Via Sfc ESCU actions · hunting P Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc ESCU actions · hunting P Windows CrowdStrike Agent Registry Key Removal ESCU actions · hunting P Windows Defender ASR or Threat Configuration Tamper ESCU actions · alerting P Windows Defender Exclusion Registry Entry ESCU actions · alerting P Windows Disable or Modify Tools Via Taskkill ESCU actions · hunting P Windows Disable or Stop Browser Process ESCU actions · alerting P Windows DisableAntiSpyware Registry ESCU actions · alerting P Windows DISM Remove Defender ESCU actions · alerting P Windows EDRSilencer Execution ESCU actions · hunting P Windows Event For Service Disabled ESCU actions · hunting P Windows Excessive Disabled Services Event ESCU actions · alerting P Windows Filtering Platform Policy Added to Block EDR Process ESCU actions · alerting P Windows Impair Defense Add Xml Applocker Rules ESCU actions · hunting P Windows Impair Defense Change Win Defender Health Check Intervals ESCU actions · alerting P Windows Impair Defense Change Win Defender Quick Scan Interval ESCU actions · alerting P Windows Impair Defense Change Win Defender Throttle Rate ESCU actions · alerting P Windows Impair Defense Change Win Defender Tracing Level ESCU actions · alerting P Windows Impair Defense Configure App Install Control ESCU actions · alerting P Windows Impair Defense Define Win Defender Threat Action ESCU actions · alerting P Windows Impair Defense Delete Win Defender Context Menu ESCU actions · hunting P Windows Impair Defense Delete Win Defender Profile Registry ESCU actions · hunting P Windows Impair Defense Deny Security Software With Applocker ESCU actions · alerting P Windows Impair Defense Disable Controlled Folder Access ESCU actions · alerting P Windows Impair Defense Disable Defender Firewall And Network ESCU actions · alerting P Windows Impair Defense Disable Defender Protocol Recognition ESCU actions · alerting P Windows Impair Defense Disable PUA Protection ESCU actions · alerting P Windows Impair Defense Disable Realtime Signature Delivery ESCU actions · alerting P Windows Impair Defense Disable Web Evaluation ESCU actions · alerting P Windows Impair Defense Disable Win Defender App Guard ESCU actions · alerting P Windows Impair Defense Disable Win Defender Compute File Hashes ESCU actions · alerting P Windows Impair Defense Disable Win Defender Gen reports ESCU actions · alerting P Windows Impair Defense Disable Win Defender Network Protection ESCU actions · alerting P Windows Impair Defense Disable Win Defender Report Infection ESCU actions · alerting P Windows Impair Defense Disable Win Defender Scan On Update ESCU actions · alerting P Windows Impair Defense Disable Win Defender Signature Retirement ESCU actions · alerting P Windows Impair Defense Overide Win Defender Phishing Filter ESCU actions · alerting P Windows Impair Defense Override SmartScreen Prompt ESCU actions · alerting P Windows Impair Defense Set Win Defender Smart Screen Level To Warn ESCU actions · alerting P Windows Impair Defenses Disable Auto Logger Session ESCU actions · hunting P Windows Impair Defenses Disable HVCI ESCU actions · alerting P Windows Impair Defenses Disable Win Defender Auto Logging ESCU actions · hunting P Windows Important Audit Policy Disabled ESCU actions · alerting P Windows Increase in Group or Object Modification Activity ESCU actions · alerting P Windows Increase in User Modification Activity ESCU actions · alerting P Windows MpCmdRun RemoveDefinitions Execution ESCU actions · hunting P Windows Outlook Dialogs Disabled from Unusual Process ESCU actions · alerting P Windows Powershell Import Applocker Policy ESCU actions · alerting P Windows Raccine Scheduled Task Deletion ESCU actions · alerting P Windows Registry Delete Task SD ESCU actions · hunting P Windows Registry Dotnet ETW Disabled Via ENV Variable ESCU actions · alerting P Windows Terminating Lsass Process ESCU actions · hunting P Wmic NonInteractive App Uninstallation ESCU actions · hunting P Cisco Configuration Archive Logging Analysis ESCU actions · hunting P Cisco SNMP Community String Configuration Changes ESCU actions · hunting P