// MITRE ATT&CK

🎯 Defense Impairment TA0112

MITRE ATT&CK techniques under the Defense Impairment tactic (56). Each explains the "how" the adversary pursues in this phase.

T1687
Exploitation for Defense Impairment
T1556.003
Pluggable Authentication Modules
T1578.004
Revert Cloud Instance
T1222.002
Linux and Mac Permissions
T1666
Modify Cloud Resource Hierarchy
T1685.003
Modify or Spoof Tool UI
T1685.001
Disable or Modify Windows Event Log
T1578
Modify Cloud Compute Infrastructure
T1600
Weaken Encryption
T1685.004
Disable or Modify Linux Audit System Log
T1484.002
Trust Modification
T1686.003
Windows Host Firewall
T1689
Downgrade Attack
T1553.001
Gatekeeper Bypass
T1553.002
Code Signing
T1222.001
Windows Permissions
T1685.002
Disable or Modify Cloud Log
T1556.002
Password Filter DLL
T1600.001
Reduce Key Space
T1599.001
Network Address Translation Traversal
T1553.003
SIP and Trust Provider Hijacking
T1556.007
Hybrid Identity
T1207
Rogue Domain Controller
T1553.006
Code Signing Policy Modification
T1112
Modify Registry
T1484.001
Group Policy Modification
T1685.006
Clear Linux or Mac System Logs
T1222
File and Directory Permissions Modification
T1578.003
Delete Cloud Instance
T1685.005
Clear Windows Event Logs
T1647
Plist File Modification
T1553.005
Mark-of-the-Web Bypass
T1600.002
Disable Crypto Hardware
T1556.008
Network Provider DLL
T1686.002
Network Device Firewall
T1601
Modify System Image
T1556.006
Multi-Factor Authentication
T1599
Network Boundary Bridging
T1690
Prevent Command History Logging
T1553
Subvert Trust Controls
T1685
Disable or Modify Tools
T1553.004
Install Root Certificate
T1688
Safe Mode Boot
T1578.005
Modify Cloud Compute Configurations
T1556.009
Conditional Access Policies
T1578.002
Create Cloud Instance
T1601.001
Patch System Image
T1556.001
Domain Controller Authentication
T1556.005
Reversible Encryption
T1484
Domain or Tenant Policy Modification
T1578.001
Create Snapshot
T1686.001
Cloud Firewall
T1686
Disable or Modify System Firewall
T1556
Modify Authentication Process
T1556.004
Network Device Authentication
T1601.002
Downgrade System Image

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.