// MITRE ATT&CK
T1685 · Disable or Modify Tools
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specifi...
¿Cómo detectarlo y mitigarlo?
La detección de Disable or Modify Tools parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (6)
T1685.001
Disable or Modify Windows Event Log T1685.002
Disable or Modify Cloud Log T1685.003
Modify or Spoof Tool UI T1685.004
Disable or Modify Linux Audit System Log T1685.005
Clear Windows Event Logs T1685.006
Clear Linux or Mac System Logs
Disable or Modify Windows Event Log T1685.002
Disable or Modify Cloud Log T1685.003
Modify or Spoof Tool UI T1685.004
Disable or Modify Linux Audit System Log T1685.005
Clear Windows Event Logs T1685.006
Clear Linux or Mac System Logs
Técnicas relacionadas
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.