// MITRE ATT&CK
T1685.003 · Modify or Spoof Tool UI
Sub-technique of T1685 · Disable or Modify Tools.
Adversaries may spoof or manipulate security tool user interfaces (UIs) to falsely indicate tools are functioning normally and delay detection and response. Adversaries may present misleading or falsified security tool interfaces (UIs) that display normal or healthy status indicators, even when un...
How to detect & mitigate it
Detecting Modify or Spoof Tool UI starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure T1600
Weaken Encryption
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.001
Disable or Modify Windows Event Log T1578
Modify Cloud Compute Infrastructure T1600
Weaken Encryption
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.