{"id":"T1685","name":"Disable or Modify Tools","url":"https://attack.mitre.org/techniques/T1685","tactics":["defense-impairment"],"platforms":["Containers","ESXi","IaaS","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0497","stix_id":"x-mitre-detection-strategy--a21019ad-f6d2-4806-be7b-01ba27c63147","name":"Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.","url":"https://attack.mitre.org/detectionstrategies/DET0497","analytics":[{"id":"AN1369","stix_id":"x-mitre-analytic--7faf6f37-f074-4b9d-be19-618c3516486d","name":"Analytic 1369","description":"Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN1369","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=5","data_component":"DC0033","data_component_name":"Process Termination","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ProcessNameExclusions","description":"List of expected administrative tools/processes to prevent false positives."},{"field":"TimeWindow","description":"Defines correlation window linking process termination, registry edits, and service stoppage."},{"field":"ServiceNames","description":"Customizable list of security service names per enterprise deployment."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]},{"id":"AN1370","stix_id":"x-mitre-analytic--bda03bab-3f0b-4bd0-8a8f-77bcb2b1ee7d","name":"Analytic 1370","description":"Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN1370","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: systemctl stop, service stop, or kill -9 on security daemons (e.g., falcon-sensor, auditd)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:CONFIG_CHANGE","channel":"delete: Modification of systemd unit files or config for security agents","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"auditd-config-change"}],"mutable_elements":[{"field":"AgentServiceNames","description":"List of endpoint protection service names (varies across deployments)."},{"field":"AllowedAdminAccounts","description":"Accounts permitted to legitimately stop or reconfigure services."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]},{"id":"AN1371","stix_id":"x-mitre-analytic--9e9a5111-038b-4c68-a8bc-6d094723def4","name":"Analytic 1371","description":"Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN1371","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of launchctl unload, kill, or removal of security agent daemons","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Modification of system configuration profiles affecting security tools","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DaemonNames","description":"Expected security agent daemons (e.g., com.crowdstrike.falcon.Agent)."},{"field":"TimeWindow","description":"Detection correlation period for multiple security tool disable actions."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]},{"id":"AN1372","stix_id":"x-mitre-analytic--5d329e39-a38b-47cd-8d3d-fa7515280fd7","name":"Analytic 1372","description":"Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN1372","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"Delete* / Stop*: DeleteAlarms, StopLogging, or DisableMonitoring API calls","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"APIActions","description":"Customizable list of cloud provider API calls related to monitoring/alerting disablement."},{"field":"UserContext","description":"Distinguishes adversary actions from authorized DevOps/CloudOps activities."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]},{"id":"AN1373","stix_id":"x-mitre-analytic--f421cbe1-d42e-45e9-adad-12c6ed0a5cb8","name":"Analytic 1373","description":"Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents.","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN1373","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:audit","channel":"kubectl delete or patch of security pods/admission controllers","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"kubernetes-audit"}],"mutable_elements":[{"field":"NamespaceExclusions","description":"Exclusion of namespaces where temporary deletion of monitoring tools is legitimate (e.g., staging)."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]},{"id":"AN1374","stix_id":"x-mitre-analytic--e542342f-5a08-408d-b292-797bcb2da5eb","name":"Analytic 1374","description":"Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility.","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN1374","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:config","channel":"write: Startup configuration changes disabling security checks","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"networkdevice-config"},{"name":"networkdevice:syslog","channel":"no logging host, no aaa new-model, no snmp-server, commit","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"ConfigBaseline","description":"Reference configuration state for detecting unauthorized modifications."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]},{"id":"AN2044","stix_id":"x-mitre-analytic--2b990a38-dedf-4a9a-9bd2-9a805c2f1b46","name":"Analytic 2044","description":"Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity.","url":"https://attack.mitre.org/detectionstrategies/DET0497#AN2044","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"esxcli system syslog config set/reload, services.sh restart/stop","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"esxi:hostd","channel":"service state change","data_component":"DC0065","data_component_name":"Service Modification","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"ExpectedAdminIPs","description":"Authorized management sources."}],"live":true,"detection_strategies":["DET0497"],"techniques":["T1685"]}],"live":true,"version":"1.1","techniques":["T1685"]}],"sigma_rules":[{"id":"023c654f-8f16-44d9-bb2b-00ff36a62af9","title":"Python Function Execution Security Warning Disabled In Excel","author":"@Kostastsale","status":"test","level":"high","date":"2023-08-22","modified":null,"description":"Detects changes to the registry value \"PythonFunctionWarnings\" that would prevent any warnings or alerts from showing when Python functions are about to be executed.\nThreat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.\n","references":["https://support.microsoft.com/en-us/office/data-security-and-python-in-excel-33cc88a4-4a87-485e-9ff9-f35958278327"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_registry_office_disable_python_security_warnings.yml","techniques":["T1685"],"cves":[]},{"id":"02cf536a-cf21-4876-8842-4159c8aee3cc","title":"Github Push Protection Bypass Detected","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"low","date":"2024-03-07","modified":null,"description":"Detects when a user bypasses the push protection on a secret detected by secret scanning.","references":["https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/push-protection-for-repositories-and-organizations","https://thehackernews.com/2024/03/github-rolls-out-default-secret.html"],"logsource":{"product":"github","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/github/audit/github_push_protection_bypass_detected.yml","techniques":["T1685"],"cves":[]},{"id":"0372e1f9-0fd2-40f7-be1b-a7b2b848fa7b","title":"Disable Privacy Settings Experience in Registry","author":"frack113","status":"test","level":"medium","date":"2022-10-02","modified":"2023-08-17","description":"Detects registry modifications that disable Privacy Settings Experience","references":["https://github.com/redcanaryco/atomic-red-team/blob/9e5b12c4912c07562aec7500447b11fa3e17e254/atomics/T1562.001/T1562.001.md"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_disable_privacy_settings_experience.yml","techniques":["T1685"],"cves":[]},{"id":"05b2aa93-1210-42c8-8d9a-2fcc13b284f5","title":"Service Registry Key Deleted Via Reg.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-01","modified":"2023-02-04","description":"Detects execution of \"reg.exe\" commands with the \"delete\" flag on services registry key. Often used by attacker to remove AV software services","references":["https://www.virustotal.com/gui/file/2bcd5702a7565952c44075ac6fb946c7780526640d1264f692c7664c02c68465"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_delete_services.yml","techniques":["T1685"],"cves":[]},{"id":"07e3cb2c-0608-410d-be4b-1511cb1a0448","title":"Tamper Windows Defender Remove-MpPreference","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-05","modified":null,"description":"Detects attempts to remove Windows Defender configurations using the 'MpPreference' cmdlet","references":["https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/windows-10-controlled-folder-access-event-search/ba-p/2326088"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_remove_mppreference.yml","techniques":["T1685"],"cves":[]},{"id":"09706624-b7f6-455d-9d02-adee024cee1d","title":"HackTool - CobaltStrike BOF Injection Pattern","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-08-04","modified":"2023-11-28","description":"Detects a typical pattern of a CobaltStrike BOF which inject into other processes","references":["https://github.com/boku7/injectAmsiBypass","https://github.com/boku7/spawn"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.execution","attack.defense-impairment","attack.t1106","attack.t1685"],"path":"rules/windows/process_access/proc_access_win_hktl_cobaltstrike_bof_injection_pattern.yml","techniques":["T1106","T1685"],"cves":[]},{"id":"0eb46774-f1ab-4a74-8238-1155855f2263","title":"Disable Windows Defender Functionalities Via Registry Keys","author":"AlertIQ, Ján Trenčanský, frack113, Nasreddine Bencherchali, Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2022-08-01","modified":"2024-10-07","description":"Detects when attackers or tools disable Windows Defender functionalities via the Windows registry","references":["https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/","https://gist.github.com/anadr/7465a9fde63d41341136949f14c21105","https://admx.help/?Category=Windows_7_2008R2&Policy=Microsoft.Policies.WindowsDefender::SpyNetReporting","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker","https://www.tenforums.com/tutorials/32236-enable-disable-microsoft-defender-pua-protection-windows-10-a.html","https://www.tenforums.com/tutorials/105533-enable-disable-windows-defender-exploit-protection-settings.html","https://www.tenforums.com/tutorials/123792-turn-off-tamper-protection-microsoft-defender-antivirus.html","https://securelist.com/key-group-ransomware-samples-and-telegram-schemes/114025/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_windows_defender_tamper.yml","techniques":["T1685"],"cves":[]},{"id":"115fdba9-f017-42e6-84cf-d5573bf2ddf8","title":"Disable of ETW Trace - Powershell","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-28","modified":"2022-11-25","description":"Detects usage of powershell cmdlets to disable or remove ETW trace sessions","references":["https://medium.com/palantir/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","car.2016-04-002"],"path":"rules/windows/powershell/powershell_script/posh_ps_etw_trace_evasion.yml","techniques":["T1070","T1685"],"cves":[]},{"id":"121b25f7-b9d6-4b37-afa0-cba317ec52f3","title":"WDAC Policy File Creation In CodeIntegrity Folder","author":"Andreas Braathen (mnemonic.io)","status":"experimental","level":"medium","date":"2025-01-30","modified":null,"description":"Attackers can craft a custom Windows Defender Application Control (WDAC) policy that blocks Endpoint Detection and Response (EDR) components while allowing their own malicious code. The policy is placed in the privileged Windows Code Integrity folder (C:\\Windows\\System32\\CodeIntegrity\\). Upon reboot, the policy prevents EDR drivers from loading, effectively bypassing security measures and may further enable undetected lateral movement within an Active Directory environment.\n","references":["https://beierle.win/2024-12-20-Weaponizing-WDAC-Killing-the-Dreams-of-EDR/","https://www.virustotal.com/gui/file/d2a4f52a9923336f119a52e531bbb1e66f18322fd8efa9af1a64b94f4d36dc97"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.defense-impairment","attack.t1685","detection.threat-hunting"],"path":"rules-threat-hunting/windows/file/file_event/file_event_win_wdac_policy_creation_in_codeintegrity_folder.yml","techniques":["T1685"],"cves":[]},{"id":"12f6b752-042d-483e-bf9c-915a6d06ad75","title":"Windows Firewall Disabled via PowerShell","author":"Tim Rauch, Elastic (idea)","status":"test","level":"medium","date":"2022-09-14","modified":"2023-02-13","description":"Detects attempts to disable the Windows Firewall using PowerShell","references":["https://www.elastic.co/guide/en/security/current/windows-firewall-disabled-via-powershell.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_disable_firewall.yml","techniques":["T1685"],"cves":[]},{"id":"1321dc4e-a1fe-481d-a016-52c45f0c8b4f","title":"Windows Defender Exclusions Added","author":"Christian Burkard (Nextron Systems)","status":"stable","level":"medium","date":"2021-07-06","modified":"2022-12-06","description":"Detects the Setting of Windows Defender Exclusions","references":["https://twitter.com/_nullbind/status/1204923340810543109"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_config_change_exclusion_added.yml","techniques":["T1685"],"cves":[]},{"id":"14c71865-6cd3-44ae-adaa-1db923fae5f2","title":"Tamper Windows Defender - ScriptBlockLogging","author":"frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-01-16","modified":"2024-01-02","description":"Detects PowerShell scripts attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference?view=windowsserver2022-ps","https://bidouillesecurity.com/disable-windows-defender-in-powershell/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/powershell/powershell_script/posh_ps_tamper_windows_defender_set_mp.yml","techniques":["T1685"],"cves":[]},{"id":"160d2780-31f7-4922-8b3a-efce30e63e96","title":"Potential AMSI COM Server Hijacking","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-04","modified":"2023-08-17","description":"Detects changes to the AMSI come server registry key in order disable AMSI scanning functionalities. When AMSI attempts to starts its COM component, it will query its registered CLSID and return a non-existent COM server. This causes a load failure and prevents any scanning methods from being accessed, ultimately rendering AMSI useless","references":["https://enigma0x3.net/2017/07/19/bypassing-amsi-via-com-server-hijacking/","https://github.com/r00t-3xp10it/hacking-material-books/blob/43cb1e1932c16ff1f58b755bc9ab6b096046853f/obfuscation/simple_obfuscation.md#amsi-comreg-bypass"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_amsi_com_hijack.yml","techniques":["T1685"],"cves":[]},{"id":"16ab6143-510a-44e2-a615-bdb80b8317fc","title":"Bitbucket Global SSH Settings Changed","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects Bitbucket global SSH access configuration changes.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/enable-ssh-access-to-git-repositories-776640358.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.lateral-movement","attack.defense-impairment","attack.t1685","attack.t1021.004"],"path":"rules/application/bitbucket/audit/bitbucket_audit_global_ssh_settings_change_detected.yml","techniques":["T1685","T1021.004"],"cves":[]},{"id":"17769c90-230e-488b-a463-e05c08e9d48f","title":"Powershell Defender Exclusion","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2021-04-29","modified":"2022-05-12","description":"Detects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets","references":["https://learn.microsoft.com/en-us/defender-endpoint/configure-process-opened-file-exclusions-microsoft-defender-antivirus","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://twitter.com/AdamTheAnalyst/status/1483497517119590403"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_defender_exclusion.yml","techniques":["T1685"],"cves":[]},{"id":"17e53739-a1fc-4a62-b1b9-87711c2d5e44","title":"Python Function Execution Security Warning Disabled In Excel - Registry","author":"Nasreddine Bencherchali (Nextron Systems), @Kostastsale","status":"test","level":"high","date":"2024-08-23","modified":null,"description":"Detects changes to the registry value \"PythonFunctionWarnings\" that would prevent any warnings or alerts from showing when Python functions are about to be executed.\nThreat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.\n","references":["https://support.microsoft.com/en-us/office/data-security-and-python-in-excel-33cc88a4-4a87-485e-9ff9-f35958278327"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_office_disable_python_security_warnings.yml","techniques":["T1685"],"cves":[]},{"id":"1c722651-254a-4b04-a9f4-99b62a2d0a1f","title":"AWS Bedrock Guardrail Updated","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-07-10","modified":null,"description":"Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken\nmodel safety controls and allow unsafe or unauthorized model responses.\n","references":["https://docs.aws.amazon.com/bedrock/latest/APIReference/API_UpdateGuardrail.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_bedrock_guardrail_updated.yml","techniques":["T1685"],"cves":[]},{"id":"1e8a9b4d-3c2a-4f9b-8d1e-7c6a5b4f3d2e","title":"PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'","author":"Matt Anderson (Huntress)","status":"experimental","level":"high","date":"2025-07-11","modified":null,"description":"Detects the use of PowerShell to execute the 'Set-MpPreference' cmdlet to configure Windows Defender's threat severity default action to 'Allow' (value '6') or 'NoAction' (value '9').\nThis is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level.\nAn attacker might use this technique via the command line to bypass defenses before executing payloads.\n","references":["https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-threatseveritydefaultaction","https://research.splunk.com/endpoint/7215831c-8252-4ae3-8d43-db588e82f952","https://gist.github.com/Dump-GUY/8daef859f382b895ac6fd0cf094555d2","https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_defender_default_action_modified.yml","techniques":["T1685"],"cves":[]},{"id":"1ec65a5f-9473-4f12-97da-622044d6df21","title":"Powershell Defender Disable Scan Feature","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-03","modified":"2024-01-02","description":"Detects requests to disable Microsoft Defender features using PowerShell commands","references":["https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference?view=windowsserver2022-ps","https://www.virustotal.com/gui/file/d609799091731d83d75ec5d1f030571af20c45efeeb94840b67ea09a3283ab65/behavior/C2AE","https://www.virustotal.com/gui/search/content%253A%2522Set-MpPreference%2520-Disable%2522/files"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_defender_disable_feature.yml","techniques":["T1685"],"cves":[]},{"id":"1f0b4cac-9c81-41f4-95d0-8475ff46b3e2","title":"PPL Tampering Via WerFaultSecure","author":"Jason (https://github.com/0xbcf)","status":"experimental","level":"high","date":"2025-09-23","modified":"2025-11-23","description":"Detects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus).\nThis technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software.\nDistinct command line patterns help identify the specific tool:\n- WSASS usage typically shows: \"WSASS.exe WerFaultSecure.exe [PID]\" in ParentCommandLine\n- EDR-Freeze usage typically shows: \"EDR-Freeze_[version].exe [PID] [timeout]\" in ParentCommandLine\nLegitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.\n","references":["https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html","https://github.com/TwoSevenOneT/EDR-Freeze/blob/a7f61030b36fbde89871f393488f7075d2aa89f6/EDR-Freeze.cpp#L53","https://www.zerosalarium.com/2025/09/Dumping-LSASS-With-WER-On-Modern-Windows-11.html","https://github.com/TwoSevenOneT/WSASS/blob/2c8fd9fa32143e7bc9f066e9511c6f8a57bc64b5/WSASS.cpp#L251"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685","attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_werfaultsecure_abuse.yml","techniques":["T1685","T1003.001"],"cves":[]},{"id":"1f1d8209-636e-4c6c-a137-781cca8b82f9","title":"WFP Filter Added via Registry","author":"Frack113","status":"experimental","level":"medium","date":"2025-10-23","modified":null,"description":"Detects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.\n","references":["https://github.com/netero1010/EDRSilencer/blob/0e73a7037ec65c52894d8208e6f605a7da0a34a6/EDRSilencer.c","https://www.huntress.com/blog/silencing-the-edr-silencers","https://www.trendmicro.com/en_us/research/24/j/edrsilencer-disrupting-endpoint-security-solutions.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.execution","attack.defense-impairment","attack.t1685","attack.t1569.002"],"path":"rules/windows/registry/registry_set/registry_set_susp_wfp_filter_added.yml","techniques":["T1685","T1569.002"],"cves":[]},{"id":"22154f0e-5132-4a54-aa78-cc62f6def531","title":"Vulnerable Driver Blocklist Registry Tampering Via CommandLine","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-01-26","modified":null,"description":"Detects tampering of the Vulnerable Driver Blocklist registry via command line tools such as PowerShell or REG.EXE.\nThe Vulnerable Driver Blocklist is a security feature that helps prevent the loading of known vulnerable drivers.\nDisabling this feature may indicate an attempt to bypass security controls, often targeted by threat actors\nto facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response\n","references":["https://www.sophos.com/en-us/blog/sharpening-the-knife-gold-blades-strategic-evolution","https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_vulnerable_driver_blocklist_registry_tampering.yml","techniques":["T1685"],"cves":[]},{"id":"225d8b09-e714-479c-a0e4-55e6f29adf35","title":"Azure Kubernetes Events Deleted","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-07-24","modified":"2022-08-23","description":"Detects when Events are deleted in Azure Kubernetes. An adversary may delete events in Azure Kubernetes in an attempt to evade detection.","references":["https://learn.microsoft.com/en-us/azure/role-based-access-control/resource-provider-operations#microsoftkubernetes","https://github.com/elastic/detection-rules/blob/da3852b681cf1a33898b1535892eab1f3a76177a/rules/integrations/azure/defense_evasion_kubernetes_events_deleted.toml"],"logsource":{"product":"azure","service":"activitylogs"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/cloud/azure/activity_logs/azure_kubernetes_events_deleted.yml","techniques":["T1685"],"cves":[]},{"id":"272e55a4-9e6b-4211-acb6-78f51f0b1b40","title":"Folder Removed From Exploit Guard ProtectedFolders List - Registry","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-05","modified":"2023-02-08","description":"Detects the removal of folders from the \"ProtectedFolders\" list of of exploit guard. This could indicate an attacker trying to launch an encryption process or trying to manipulate data inside of the protected folder","references":["https://www.microsoft.com/security/blog/2017/10/23/windows-defender-exploit-guard-reduce-the-attack-surface-against-next-generation-malware/"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_delete/registry_delete_exploit_guard_protected_folders.yml","techniques":["T1685"],"cves":[]},{"id":"30edb182-aa75-42c0-b0a9-e998bb29067c","title":"Potential AMSI Bypass Via .NET Reflection","author":"Markus Neis, @Kostastsale","status":"test","level":"high","date":"2018-08-17","modified":"2023-02-03","description":"Detects Request to \"amsiInitFailed\" that can be used to disable AMSI Scanning","references":["https://s3cur3th1ssh1t.github.io/Bypass_AMSI_by_manual_modification/","https://www.mdsec.co.uk/2018/06/exploring-powershell-amsi-and-logging-evasion/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_amsi_init_failed_bypass.yml","techniques":["T1685"],"cves":[]},{"id":"31e124fb-5dc4-42a0-83b3-44a69c77b271","title":"Antivirus Filter Driver Disallowed On Dev Drive - Registry","author":"@kostastsale, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-11-05","modified":"2024-08-16","description":"Detects activity that indicates a user disabling the ability for Antivirus mini filter to inspect a \"Dev Drive\".\n","references":["https://twitter.com/0gtweet/status/1720419490519752955"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_devdrv_disallow_antivirus_filter.yml","techniques":["T1685"],"cves":[]},{"id":"360a1340-398a-46b6-8d06-99b905dc69d2","title":"Windows Defender Grace Period Expired","author":"Ján Trenčanský, frack113","status":"stable","level":"high","date":"2020-07-28","modified":"2023-11-22","description":"Detects the expiration of the grace period of Windows Defender. This means protection against viruses, spyware, and other potentially unwanted software is disabled.\n","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide#event-id-5101","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://craigclouditpro.wordpress.com/2020/03/04/hunting-malicious-windows-defender-activity/"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_antimalware_platform_expired.yml","techniques":["T1685"],"cves":[]},{"id":"36388120-b3f1-4ce9-b50b-280d9a7f4c04","title":"Kaspersky Endpoint Security Stopped Via CommandLine - Linux","author":"Milad Cheraghi","status":"experimental","level":"high","date":"2025-10-18","modified":null,"description":"Detects execution of the Kaspersky init.d stop script on Linux systems either directly or via systemctl.\nThis activity may indicate a manual interruption of the antivirus service by an administrator, or it could be a sign of potential tampering or evasion attempts by malicious actors.\n","references":["https://support.kaspersky.com/KES4Linux/12.0.0/en-US/197929.htm"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1685"],"path":"rules/linux/process_creation/proc_creation_lnx_av_kaspersky_av_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"3669afd2-9891-4534-a626-e5cf03810a61","title":"Load Of RstrtMgr.DLL By An Uncommon Process","author":"Luc Génaux","status":"test","level":"low","date":"2023-11-28","modified":"2026-07-28","description":"Detects the load of RstrtMgr DLL (Restart Manager) by an uncommon process.\nThis library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows.\nIt could also be used for anti-analysis purposes by shut downing specific processes.\n","references":["https://www.crowdstrike.com/blog/windows-restart-manager-part-1/","https://www.crowdstrike.com/blog/windows-restart-manager-part-2/","https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/","https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.impact","attack.defense-impairment","attack.t1486","attack.t1685"],"path":"rules/windows/image_load/image_load_dll_rstrtmgr_uncommon_load.yml","techniques":["T1486","T1685"],"cves":[]},{"id":"387df17d-3b04-448f-8669-9e7fd5e5fd8c","title":"Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-27","modified":null,"description":"Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques.\nThis technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.\n","references":["https://blog.axelarator.net/hunting-for-edr-freeze/"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_access/proc_access_win_werfaultsecure_msmpeng_access.yml","techniques":["T1685"],"cves":[]},{"id":"3883d9a0-fd0f-440f-afbb-445a2a799bb8","title":"Github Secret Scanning Feature Disabled","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"high","date":"2024-03-07","modified":"2024-07-19","description":"Detects if the secret scanning feature is disabled for an enterprise or repository.","references":["https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/about-secret-scanning"],"logsource":{"product":"github","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/github/audit/github_secret_scanning_feature_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"38eb1dbb-011f-40b1-a126-cf03a0210563","title":"ESXi Syslog Configuration Change Via ESXCLI","author":"Cedric Maurugeon","status":"test","level":"medium","date":"2023-09-04","modified":null,"description":"Detects changes to the ESXi syslog configuration via \"esxcli\"","references":["https://support.solarwinds.com/SuccessCenter/s/article/Configure-ESXi-Syslog-to-LEM?language=en_US","https://developer.broadcom.com/xapis/esxcli-command-reference/7.0.0/namespace/esxcli_system.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1685","attack.t1690","attack.t1059.012"],"path":"rules/linux/process_creation/proc_creation_lnx_esxcli_syslog_config_change.yml","techniques":["T1685","T1690","T1059.012"],"cves":[]},{"id":"3da70954-0f2c-4103-adff-b7440368f50e","title":"Suspicious PROCEXP152.sys File Created In TMP","author":"xknow (@xknow_infosec), xorxes (@xor_xes)","status":"test","level":"medium","date":"2019-04-08","modified":"2026-06-29","description":"Detects the creation of the PROCEXP152.sys file in the application-data local temporary folder.\nThis driver is used by Sysinternals Process Explorer but also by KDU (https://github.com/hfiref0x/KDU) or Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU.\n","references":["https://web.archive.org/web/20230331181619/https://blog.dylan.codes/evading-sysmon-and-windows-event-logging/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/file/file_event/file_event_win_susp_procexplorer_driver_created_in_tmp_folder.yml","techniques":["T1685"],"cves":[]},{"id":"41421f44-58f9-455d-838a-c398859841d4","title":"ETW Logging Tamper In .NET Processes Via CommandLine","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"high","date":"2020-05-02","modified":"2022-12-09","description":"Detects changes to environment variables related to ETW logging via the CommandLine.\nThis could indicate potential adversaries stopping ETW providers recording loaded .NET assemblies.\n","references":["https://twitter.com/_xpn_/status/1268712093928378368","https://social.msdn.microsoft.com/Forums/vstudio/en-US/0878832e-39d7-4eaf-8e16-a729c4c40975/what-can-i-use-e13c0d23ccbc4e12931bd9cc2eee27e4-for?forum=clr","https://github.com/dotnet/runtime/blob/ee2355c801d892f2894b0f7b14a20e6cc50e0e54/docs/design/coreclr/jit/viewing-jit-dumps.md#setting-configuration-variables","https://github.com/dotnet/runtime/blob/f62e93416a1799aecc6b0947adad55a0d9870732/src/coreclr/src/inc/clrconfigvalues.h#L35-L38","https://github.com/dotnet/runtime/blob/7abe42dc1123722ed385218268bb9fe04556e3d3/src/coreclr/src/inc/clrconfig.h#L33-L39","https://github.com/dotnet/runtime/search?p=1&q=COMPlus_&unscoped_q=COMPlus_","https://bunnyinside.com/?term=f71e8cb9c76a","http://managed670.rssing.com/chan-5590147/all_p1.html","https://github.com/dotnet/runtime/blob/4f9ae42d861fcb4be2fcd5d3d55d5f227d30e723/docs/coding-guidelines/clr-jit-coding-conventions.md#1412-disabling-code","https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_susp_etw_modification_cmdline.yml","techniques":["T1685"],"cves":[]},{"id":"416bc4a2-7217-4519-8dc7-c3271817f1d5","title":"Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-27","modified":"2026-01-09","description":"Detects loading of dbgcore.dll or dbghelp.dll from uncommon locations such as user directories.\nThese DLLs contain the MiniDumpWriteDump function, which can be abused for credential dumping purposes or in some cases for evading EDR/AV detection by suspending processes.\n","references":["https://blog.axelarator.net/hunting-for-edr-freeze/","https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html","https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1003","attack.t1685"],"path":"rules/windows/image_load/image_load_win_susp_dbgcore_dbghelp_load.yml","techniques":["T1003","T1685"],"cves":[]},{"id":"41d1058a-aea7-4952-9293-29eaaf516465","title":"Removal Of AMSI Provider Registry Keys","author":"frack113","status":"test","level":"high","date":"2021-06-07","modified":"2025-10-07","description":"Detects the deletion of AMSI provider registry key entries in HKLM\\Software\\Microsoft\\AMSI. This technique could be used by an attacker in order to disable AMSI inspection.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://seclists.org/fulldisclosure/2020/Mar/45"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_delete/registry_delete_removal_amsi_registry_key.yml","techniques":["T1685"],"cves":[]},{"id":"42205c73-75c8-4a63-9db1-e3782e06fda0","title":"Suspicious Application Allowed Through Exploit Guard","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-05","modified":"2023-08-17","description":"Detects applications being added to the \"allowed applications\" list of exploit guard in order to bypass controlled folder settings","references":["https://www.microsoft.com/security/blog/2017/10/23/windows-defender-exploit-guard-reduce-the-attack-surface-against-next-generation-malware/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_exploit_guard_susp_allowed_apps.yml","techniques":["T1685"],"cves":[]},{"id":"42ccce6d-7bd3-4930-95cd-e4d83fa94a30","title":"Bitbucket Project Secret Scanning Allowlist Added","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"low","date":"2024-02-25","modified":null,"description":"Detects when a secret scanning allowlist rule is added for projects.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/bitbucket/audit/bitbucket_audit_project_secret_scanning_allowlist_added.yml","techniques":["T1685"],"cves":[]},{"id":"43e32da2-fdd0-4156-90de-50dfd62636f9","title":"Dism Remove Online Package","author":"frack113","status":"test","level":"medium","date":"2022-01-16","modified":"2022-08-26","description":"Deployment Image Servicing and Management tool. DISM is used to enumerate, install, uninstall, configure, and update features and packages in Windows images","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md#atomic-test-26---disable-windows-defender-with-dism","https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_dism_remove.yml","techniques":["T1685"],"cves":[]},{"id":"44e24481-6202-4c62-9127-5a0ae8e3fe3d","title":"Obfuscated PowerShell OneLiner Execution","author":"@Kostastsale, TheDFIRReport","status":"test","level":"high","date":"2022-05-09","modified":"2025-04-16","description":"Detects the execution of a specific OneLiner to download and execute powershell modules in memory.","references":["https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/","https://gist.github.com/mgeeky/3b11169ab77a7de354f4111aa2f0df38"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1059.001","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_download_cradle_obfuscated.yml","techniques":["T1059.001","T1685"],"cves":[]},{"id":"452bce90-6fb0-43cc-97a5-affc283139b3","title":"Suspicious Windows Defender Registry Key Tampering Via Reg.EXE","author":"Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-03-22","modified":"2025-06-04","description":"Detects the usage of \"reg.exe\" to tamper with different Windows Defender registry keys in order to disable some important features related to protection and detection\n","references":["https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/","https://github.com/swagkarna/Defeat-Defender-V1.2.0/tree/ae4059c4276da6f6303b8f53cdff085ecae88a91","https://www.elevenforum.com/t/video-guide-how-to-completely-disable-microsoft-defender-antivirus.14608/page-2","https://tria.ge/241231-j9yatstqbm/behavioral1"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_windows_defender_tamper.yml","techniques":["T1685"],"cves":[]},{"id":"46a68649-f218-4f86-aea1-16a759d81820","title":"Windows Defender Exclusion List Modified","author":"@BarryShooshooga","status":"test","level":"medium","date":"2019-10-26","modified":"2023-11-11","description":"Detects modifications to the Windows Defender exclusion registry key. This could indicate a potentially suspicious or even malicious activity by an attacker trying to add a new exclusion in order to bypass security.\n","references":["https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/security/win_security_windows_defender_exclusions_registry_modified.yml","techniques":["T1685"],"cves":[]},{"id":"48917adc-a28e-4f5d-b729-11e75da8941f","title":"Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE","author":"frack113","status":"test","level":"medium","date":"2022-02-13","modified":"2023-02-04","description":"Detects the usage of \"reg.exe\" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.","references":["https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/","https://redcanary.com/threat-detection-report/threats/qbot/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_defender_exclusion.yml","techniques":["T1685"],"cves":[]},{"id":"4916a35e-bfc4-47d0-8e25-a003d7067061","title":"Sysmon Driver Altitude Change","author":"B.Talebi","status":"test","level":"high","date":"2022-07-28","modified":"2024-03-25","description":"Detects changes in Sysmon driver altitude value.\nIf the Sysmon driver is configured to load at an altitude of another registered service, it will fail to load at boot.\n","references":["https://posts.specterops.io/shhmon-silencing-sysmon-via-driver-unload-682b5be57650","https://youtu.be/zSihR3lTf7g"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_change_sysmon_driver_altitude.yml","techniques":["T1685"],"cves":[]},{"id":"4931188c-178e-4ee7-a348-39e8a7a56821","title":"Filter Driver Unloaded Via Fltmc.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-13","modified":"2025-10-07","description":"Detect filter driver unloading activity via fltmc.exe","references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon","https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","attack.t1685.001"],"path":"rules/windows/process_creation/proc_creation_win_fltmc_unload_driver.yml","techniques":["T1070","T1685","T1685.001"],"cves":[]},{"id":"49e5bc24-8b86-49f1-b743-535f332c2856","title":"Microsoft Defender Tamper Protection Trigger","author":"Bhabesh Raj, Nasreddine Bencherchali","status":"stable","level":"high","date":"2021-07-05","modified":"2022-12-06","description":"Detects blocked attempts to change any of Defender's settings such as \"Real Time Monitoring\" and \"Behavior Monitoring\"","references":["https://bhabeshraj.com/post/tampering-with-microsoft-defenders-tamper-protection","https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_tamper_protection_trigger.yml","techniques":["T1685"],"cves":[]},{"id":"4a6713f6-3331-11ed-a261-0242ac120002","title":"Taskkill Symantec Endpoint Protection","author":"Ilya Krestinichev, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-09-13","modified":null,"description":"Detects one of the possible scenarios for disabling Symantec Endpoint Protection.\nSymantec Endpoint Protection antivirus software services incorrectly implement the protected service mechanism.\nAs a result, the NT AUTHORITY/SYSTEM user can execute the taskkill /im command several times ccSvcHst.exe /f, thereby killing the process belonging to the service, and thus shutting down the service.\n","references":["https://www.exploit-db.com/exploits/37525","https://community.spiceworks.com/topic/2195015-batch-script-to-uninstall-symantec-endpoint-protection","https://community.broadcom.com/symantecenterprise/communities/community-home/digestviewer/viewthread?MessageKey=6ce94b67-74e1-4333-b16f-000b7fd874f0&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=digestviewer"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_taskkill_sep.yml","techniques":["T1685"],"cves":[]},{"id":"4beb6ae0-f85b-41e2-8f18-8668abc8af78","title":"Sysinternals PsSuspend Suspicious Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-03-23","modified":"2026-06-29","description":"Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/pssuspend","https://twitter.com/0gtweet/status/1638069413717975046"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_pssuspend_susp_execution.yml","techniques":["T1685"],"cves":[]},{"id":"4d431012-2ab5-4db7-a84e-b29809da2172","title":"Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback","author":"X__Junior (Nextron Systems)","status":"test","level":"medium","date":"2023-11-03","modified":null,"description":"Detects enabling of the \"AllowAnonymousCallback\" registry value, which allows a remote connection between computers that do not have a trust relationship.","references":["https://learn.microsoft.com/en-us/windows/win32/wmisdk/connecting-to-wmi-remotely-starting-with-vista"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_event/registry_set_enable_anonymous_connection.yml","techniques":["T1685"],"cves":[]},{"id":"4d7cda18-1b12-4e52-b45c-d28653210df8","title":"Sysmon Driver Unloaded Via Fltmc.EXE","author":"Kirill Kiryanov, oscd.community","status":"test","level":"high","date":"2019-10-23","modified":"2023-02-13","description":"Detects possible Sysmon filter driver unloaded via fltmc.exe","references":["https://www.darkoperator.com/blog/2018/10/5/operating-offensively-against-sysmon"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","attack.t1685.001"],"path":"rules/windows/process_creation/proc_creation_win_fltmc_unload_driver_sysmon.yml","techniques":["T1070","T1685","T1685.001"],"cves":[]},{"id":"4d7f1827-1637-4def-8d8a-fd254f9454df","title":"Sysmon Application Crashed","author":"Tim Shelton","status":"test","level":"high","date":"2022-04-26","modified":"2024-01-17","description":"Detects application popup reporting a failure of the Sysmon service","references":["https://github.com/nasbench/EVTX-ETW-Resources/blob/f1b010ce0ee1b71e3024180de1a3e67f99701fe4/ETWProvidersManifests/Windows10/1803/W10_1803_Pro_19700101_17134.1/WEPExplorer/Application%20Popup.xml#L36"],"logsource":{"product":"windows","service":"system"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/system/application_popup/win_system_application_sysmon_crash.yml","techniques":["T1685"],"cves":[]},{"id":"4f281b83-0200-4b34-bf35-d24687ea57c2","title":"ETW Logging Disabled For SCM","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-12-09","modified":"2023-08-17","description":"Detects changes to the \"TracingDisabled\" key in order to disable ETW logging for services.exe (SCM)","references":["http://redplait.blogspot.com/2020/07/whats-wrong-with-etw.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.defense-impairment","attack.t1112","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_services_etw_tamper.yml","techniques":["T1112","T1685"],"cves":[]},{"id":"51cbac1e-eee3-4a90-b1b7-358efb81fa0a","title":"Potential Windows Defender Tampering Via Wmic.EXE","author":"frack113","status":"test","level":"high","date":"2022-12-11","modified":"2023-02-14","description":"Detects potential tampering with Windows Defender settings such as adding exclusion using wmic","references":["https://github.com/redcanaryco/atomic-red-team/blob/5c1e6f1b4fafd01c8d1ece85f510160fc1275fbf/atomics/T1562.001/T1562.001.md","https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/","https://www.bleepingcomputer.com/news/security/iobit-forums-hacked-to-spread-ransomware-to-its-members/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1047","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_wmic_namespace_defender.yml","techniques":["T1047","T1685"],"cves":[]},{"id":"526cc8bc-1cdc-48ad-8b26-f19bff969cec","title":"Removal Of Index Value to Hide Schedule Task - Registry","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-26","modified":"2025-10-25","description":"Detects when the \"index\" value of a scheduled task is removed or deleted from the registry. Which effectively hides it from any tooling such as \"schtasks /query\"","references":["https://blog.qualys.com/vulnerabilities-threat-research/2022/06/20/defending-against-scheduled-task-attacks-in-windows-environments"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_delete/registry_delete_schtasks_hide_task_via_index_value_removal.yml","techniques":["T1685"],"cves":[]},{"id":"545a5da6-f103-4919-a519-e9aec1026ee4","title":"Microsoft Malware Protection Engine Crash","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-09","modified":"2023-04-14","description":"This rule detects a suspicious crash of the Microsoft Malware Protection Engine","references":["https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5","https://technet.microsoft.com/en-us/library/security/4022344"],"logsource":{"product":"windows","service":"application"},"tags":["attack.stealth","attack.defense-impairment","attack.t1211","attack.t1685"],"path":"rules/windows/builtin/application/application_error/win_application_error_msmpeng_crash.yml","techniques":["T1211","T1685"],"cves":[]},{"id":"59b70e4d-dd17-44a9-b740-acf07ae3eb6a","title":"AWS Bedrock Guardrail Deleted","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-07-10","modified":null,"description":"Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove\nmodel safety controls and allow unsafe or unauthorized model responses.\n","references":["https://docs.aws.amazon.com/bedrock/latest/APIReference/API_DeleteGuardrail.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_bedrock_guardrail_deleted.yml","techniques":["T1685"],"cves":[]},{"id":"5a9e1b2c-8f7d-4a1e-9b3c-0f6d7e5a4b1f","title":"Windows Defender Threat Severity Default Action Modified","author":"Matt Anderson (Huntress)","status":"experimental","level":"high","date":"2025-07-11","modified":null,"description":"Detects modifications or creations of Windows Defender's default threat action settings based on severity to 'allow' or take 'no action'.\nThis is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level,\nallowing malicious software to run unimpeded. An attacker might use this technique to bypass defenses before executing payloads.\n","references":["https://learn.microsoft.com/en-us/powershell/module/defender/set-mppreference","https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-threatseveritydefaultaction","https://research.splunk.com/endpoint/7215831c-8252-4ae3-8d43-db588e82f952","https://gist.github.com/Dump-GUY/8daef859f382b895ac6fd0cf094555d2","https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_event/registry_event_defender_threat_action_modified.yml","techniques":["T1685"],"cves":[]},{"id":"5b16df71-8615-4f7f-ac9b-6c43c0509e61","title":"Hide Schedule Task Via Index Value Tamper","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-26","modified":"2023-08-17","description":"Detects when the \"index\" value of a scheduled task is modified from the registry\nWhich effectively hides it from any tooling such as \"schtasks /query\" (Read the referenced link for more information about the effects of this technique)\n","references":["https://blog.qualys.com/vulnerabilities-threat-research/2022/06/20/defending-against-scheduled-task-attacks-in-windows-environments"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_hide_scheduled_task_via_index_tamper.yml","techniques":["T1685"],"cves":[]},{"id":"5e95028c-5229-4214-afae-d653d573d0ec","title":"Security Service Disabled Via Reg.EXE","author":"Florian Roth (Nextron Systems), John Lambert (idea), elhoim","status":"test","level":"high","date":"2021-07-14","modified":"2023-06-05","description":"Detects execution of \"reg.exe\" to disable security services such as Windows Defender.","references":["https://twitter.com/JohnLaTwC/status/1415295021041979392","https://github.com/gordonbay/Windows-On-Reins/blob/e587ac7a0407847865926d575e3c46f68cf7c68d/wor.ps1","https://vms.drweb.fr/virus/?i=24144899","https://bidouillesecurity.com/disable-windows-defender-in-powershell/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_disable_sec_services.yml","techniques":["T1685"],"cves":[]},{"id":"6225c53a-a96e-4235-b28f-8d7997cd96eb","title":"Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-01-26","modified":null,"description":"Detects the tampering of Hypervisor-protected Code Integrity (HVCI) related registry values via command line tool reg.exe.\nHVCI uses virtualization-based security to protect code integrity by ensuring that only trusted code can run in kernel mode.\nAdversaries may tamper with HVCI to load malicious or unsigned drivers, which can be used to escalate privileges, maintain persistence, or evade security mechanisms.\n","references":["https://www.sophos.com/en-us/blog/sharpening-the-knife-gold-blades-strategic-evolution","https://learn.microsoft.com/en-us/windows/security/hardware-security/enable-virtualization-based-protection-of-code-integrity"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_hvci_registry_tampering.yml","techniques":["T1685"],"cves":[]},{"id":"62b20d44-1546-4e61-afce-8e175eb9473c","title":"Service StartupType Change Via PowerShell Set-Service","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-03-04","modified":null,"description":"Detects the use of the PowerShell \"Set-Service\" cmdlet to change the startup type of a service to \"disabled\" or \"manual\"","references":["https://www.virustotal.com/gui/file/38283b775552da8981452941ea74191aa0d203edd3f61fb2dee7b0aea3514955"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_set_service_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"64c41342-6b27-523b-5d3f-c265f3efcdb3","title":"Terminate Linux Process Via Kill","author":"Tuan Le (NCSGroup)","status":"test","level":"medium","date":"2023-03-16","modified":"2024-12-12","description":"Detects usage of command line tools such as \"kill\", \"pkill\" or \"killall\" to terminate or signal a running process.","references":["https://www.trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html","https://www.cyberciti.biz/faq/how-force-kill-process-linux/","https://www.geeksforgeeks.org/how-to-kill-processes-on-the-linux-desktop-with-xkill/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685","detection.threat-hunting"],"path":"rules-threat-hunting/linux/process_creation/proc_creation_lnx_susp_process_termination_via_kill.yml","techniques":["T1685"],"cves":[]},{"id":"686c0b4b-9dd3-4847-9077-d6c1bbe36fcb","title":"Windows Defender Virus Scanning Feature Disabled","author":"Ján Trenčanský, frack113","status":"stable","level":"high","date":"2020-07-28","modified":"2023-11-22","description":"Detects disabling of the Windows Defender virus scanning feature","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide#event-id-5012","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://craigclouditpro.wordpress.com/2020/03/04/hunting-malicious-windows-defender-activity/"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_virus_scan_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"6a5f68d1-c4b5-46b9-94ee-5324892ea939","title":"Uninstall Sysinternals Sysmon","author":"frack113","status":"test","level":"high","date":"2022-01-12","modified":"2026-06-29","description":"Detects the removal of Sysmon, which could be a potential attempt at defense evasion","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md#atomic-test-11---uninstall-sysmon"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_sysmon_uninstall.yml","techniques":["T1685"],"cves":[]},{"id":"6aa12161-235a-4dfb-9c74-fe08df8d8da1","title":"Bitbucket Audit Log Configuration Updated","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects changes to the bitbucket audit log configuration.","references":["https://confluence.atlassian.com/bitbucketserver/view-and-configure-the-audit-log-776640417.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/bitbucket/audit/bitbucket_audit_log_configuration_update_detected.yml","techniques":["T1685"],"cves":[]},{"id":"6c0a7755-6d31-44fa-80e1-133e57752680","title":"Windows Defender Threat Detection Service Disabled","author":"Ján Trenčanský, frack113","status":"stable","level":"medium","date":"2020-07-28","modified":"2024-07-02","description":"Detects when the \"Windows Defender Threat Protection\" service is disabled.","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md"],"logsource":{"product":"windows","service":"system"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/system/service_control_manager/win_system_defender_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"6c82cf5c-090d-4d57-9188-533577631108","title":"Microsoft Malware Protection Engine Crash - WER","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-09","modified":"2023-04-14","description":"This rule detects a suspicious crash of the Microsoft Malware Protection Engine","references":["https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5","https://technet.microsoft.com/en-us/library/security/4022344"],"logsource":{"product":"windows","service":"application"},"tags":["attack.stealth","attack.defense-impairment","attack.t1211","attack.t1685"],"path":"rules/windows/builtin/application/windows_error_reporting/win_application_msmpeng_crash_wer.yml","techniques":["T1211","T1685"],"cves":[]},{"id":"6e61ee20-ce00-4f8d-8aee-bedd8216f7e3","title":"AWS GuardDuty Important Change","author":"faloker","status":"test","level":"high","date":"2020-02-11","modified":"2022-10-09","description":"Detects updates of the GuardDuty list of trusted IPs, perhaps to disable security alerts against malicious IPs.","references":["https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/guardduty__whitelist_ip/main.py#L9"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/cloud/aws/cloudtrail/aws_guardduty_disruption.yml","techniques":["T1685"],"cves":[]},{"id":"73921b9c-cafd-4446-b0c6-fdb0ace42bc0","title":"Windows Credential Guard Disabled - Registry","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-12-26","modified":null,"description":"Detects attempts to disable Windows Credential Guard by setting registry values to 0. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them.\nAdversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.\n","references":["https://woshub.com/disable-credential-guard-windows/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_credential_guard_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"75f7a0e2-7154-4c4d-9eae-5cdb4e0a5c13","title":"Write Protect For Storage Disabled","author":"Sreeman","status":"test","level":"medium","date":"2021-06-11","modified":"2024-01-18","description":"Detects applications trying to modify the registry in order to disable any write-protect property for storage devices.\nThis could be a precursor to a ransomware attack and has been an observed technique used by cypherpunk group.\n","references":["https://www.manageengine.com/products/desktop-central/os-imaging-deployment/media-is-write-protected.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_write_protect_for_storage_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"7a4d9232-92fc-404d-8ce1-4c92e7caf539","title":"HackTool - Stracciatella Execution","author":"pH-T (Nextron Systems)","status":"test","level":"high","date":"2023-04-17","modified":"2024-11-23","description":"Detects Stracciatella which executes a Powershell runspace from within C# (aka SharpPick technique) with AMSI, ETW and Script Block Logging disabled based on PE metadata characteristics.","references":["https://github.com/mgeeky/Stracciatella"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1059","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_hktl_stracciatella_execution.yml","techniques":["T1059","T1685"],"cves":[]},{"id":"7b544661-69fc-419f-9a59-82ccc328f205","title":"Potential Ke3chang/TidePool Malware Activity","author":"Markus Neis, Swisscom","status":"test","level":"high","date":"2020-06-18","modified":"2023-03-10","description":"Detects registry modifications potentially related to the Ke3chang/TidePool malware as seen in campaigns running in 2019 and 2020","references":["https://web.archive.org/web/20200618080300/https://www.verfassungsschutz.de/embed/broschuere-2020-06-bfv-cyber-brief-2020-01.pdf","https://unit42.paloaltonetworks.com/operation-ke3chang-resurfaces-with-new-tidepool-malware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.g0004","attack.t1685","detection.emerging-threats"],"path":"rules-emerging-threats/2020/Malware/Ke3chang-TidePool/proc_creation_win_malware_ke3chang_tidepool.yml","techniques":["T1685"],"cves":[]},{"id":"7d995e63-ec83-4aa3-89d5-8a17b5c87c86","title":"Scripted Diagnostics Turn Off Check Enabled - Registry","author":"Christopher Peacock @securepeacock, SCYTHE @scythe_io","status":"test","level":"medium","date":"2022-06-15","modified":"2023-08-17","description":"Detects enabling TurnOffCheck which can be used to bypass defense of MSDT Follina vulnerability","references":["https://twitter.com/wdormann/status/1537075968568877057?s=20&t=0lr18OAnmAGoGpma6grLUw"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_enabling_turnoffcheck.yml","techniques":["T1685"],"cves":[]},{"id":"7dbbcac2-57a0-45ac-b306-ff30a8bd2981","title":"Windows AMSI Related Registry Tampering Via CommandLine","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-12-25","modified":null,"description":"Detects tampering of AMSI (Anti-Malware Scan Interface) related registry values via command line tools such as reg.exe or PowerShell.\nAMSI provides a generic interface for applications and services to integrate with antimalware products.\nAdversaries may disable AMSI to evade detection of malicious scripts and code execution.\n","references":["https://github.com/arttoolkit/arttoolkit.github.io/blob/16d6230d009e58fd6f773f5317fd4d14c1f26004/_wadcoms/AMSI-Bypass-Jscript_amsienable.md","https://mostafayahiax.medium.com/hunting-for-amsi-bypassing-methods-9886dda0bf9d","https://www.mdsec.co.uk/2019/02/macros-and-more-with-sharpshooter-v2-0/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_amsi_registry_tampering.yml","techniques":["T1685"],"cves":[]},{"id":"7f2954d2-99c2-4d42-a065-ca36740f187b","title":"Hypervisor Enforced Paging Translation Disabled","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2024-07-05","modified":null,"description":"Detects changes to the \"DisableHypervisorEnforcedPagingTranslation\" registry value. Where the it is set to \"1\" in order to disable the Hypervisor Enforced Paging Translation feature.\n","references":["https://twitter.com/standa_t/status/1808868985678803222","https://github.com/AaLl86/WindowsInternals/blob/070dc4f317726dfb6ffd2b7a7c121a33a8659b5e/Slides/Hypervisor-enforced%20Paging%20Translation%20-%20The%20end%20of%20non%20data-driven%20Kernel%20Exploits%20(Recon2024).pdf"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_deviceguard_hypervisorenforcedpagingtranslation_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"801bd44f-ceed-4eb6-887c-11544633c0aa","title":"Windows Defender Configuration Changes","author":"Nasreddine Bencherchali (Nextron Systems)","status":"stable","level":"high","date":"2022-12-06","modified":"2023-11-24","description":"Detects suspicious changes to the Windows Defender configuration","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide","https://bidouillesecurity.com/disable-windows-defender-in-powershell/#DisableAntiSpyware"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_suspicious_features_tampering.yml","techniques":["T1685"],"cves":[]},{"id":"847d5ff3-8a31-4737-a970-aeae8fe21765","title":"Potential Tampering With Security Products Via WMIC","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-01-30","modified":"2025-12-15","description":"Detects uninstallation or termination of security products using the WMIC utility","references":["https://twitter.com/cglyer/status/1355171195654709249","https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/","https://www.mandiant.com/resources/unc2165-shifts-to-evade-sanctions","https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/","https://www.trendmicro.com/en_us/research/23/a/vice-society-ransomware-group-targets-manufacturing-companies.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_wmic_uninstall_security_products.yml","techniques":["T1685"],"cves":[]},{"id":"85c312b7-f44d-4a51-a024-d671c40b49fc","title":"Service StartupType Change Via Sc.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-01","modified":"2023-03-04","description":"Detect the use of \"sc.exe\" to change the startup type of a service to \"disabled\" or \"demand\"","references":["https://www.virustotal.com/gui/file/38283b775552da8981452941ea74191aa0d203edd3f61fb2dee7b0aea3514955"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_sc_disable_service.yml","techniques":["T1685"],"cves":[]},{"id":"85f520e7-6f5e-43ca-874c-222e5bf9c0de","title":"Devcon Execution Disabling VMware VMCI Device","author":"Matt Anderson, Dray Agha, Anna Pham (Huntress)","status":"experimental","level":"high","date":"2026-01-02","modified":null,"description":"Detects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device.\nThis can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device.\nThis has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.\n","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/devcon","https://communities.vmware.com/t5/VMware-Workstation-Pro/VMCI-driver-issues/td-p/2866060","https://github.com/search?q=devcon+disable+VMWVMCIHOSTDEV","https://huntress.com/blog/esxi-vm-escape-exploit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.defense-impairment","attack.t1543.003","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_devcon_disable_vmci_driver.yml","techniques":["T1543.003","T1685"],"cves":[]},{"id":"87911521-7098-470b-a459-9a57fc80bdfd","title":"Sysmon Configuration Update","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-03-09","modified":"2026-06-29","description":"Detects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_sysmon_config_update.yml","techniques":["T1685"],"cves":[]},{"id":"8a2f4b1c-3d5e-4f7a-9b2c-1e4f6d8a9c2b","title":"WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-27","modified":"2026-01-09","description":"Detects the loading of dbgcore.dll or dbghelp.dll by WerFaultSecure.exe, which has been observed in EDR-Freeze attacks to suspend processes and evade detection.\nHowever, this behavior has also been observed during normal software installations, so further investigation is required to confirm malicious activity.\nWhen threat hunting, look for this activity in conjunction with other suspicious processes starting, network connections, or file modifications that occur shortly after the DLL load.\nPay special attention to timing - if other malicious activities occur during or immediately after this library loading, it may indicate EDR evasion attempts.\nAlso correlate with any EDR/AV process suspension events or gaps in security monitoring during the timeframe.\n","references":["https://github.com/TwoSevenOneT/EDR-Freeze","https://blog.axelarator.net/hunting-for-edr-freeze/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.defense-impairment","attack.t1685","detection.threat-hunting"],"path":"rules-threat-hunting/windows/image_load/image_load_win_werfaultsecure_dbgcore_dbghelp_load.yml","techniques":["T1685"],"cves":[]},{"id":"8b7273a4-ba5d-4d8a-b04f-11f2900d043a","title":"Windows Hypervisor Enforced Code Integrity Disabled","author":"Nasreddine Bencherchali (Nextron Systems), Anish Bogati","status":"test","level":"high","date":"2023-03-14","modified":"2024-07-05","description":"Detects changes to the HypervisorEnforcedCodeIntegrity registry key and the \"Enabled\" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel\n","references":["https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/","https://github.com/redcanaryco/atomic-red-team/blob/04e487c1828d76df3e834621f4f893ea756d5232/atomics/T1562.001/T1562.001.md#atomic-test-43---disable-hypervisor-enforced-code-integrity-hvci"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_deviceguard_hypervisorenforcedcodeintegrity_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"8ffc5407-52e3-478f-9596-0a7371eafe13","title":"Disable PUA Protection on Windows Defender","author":"Austin Songer @austinsonger","status":"test","level":"high","date":"2021-08-04","modified":"2023-08-17","description":"Detects disabling Windows Defender PUA protection","references":["https://www.tenforums.com/tutorials/32236-enable-disable-microsoft-defender-pua-protection-windows-10-a.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_disabled_pua_protection_on_microsoft_defender.yml","techniques":["T1685"],"cves":[]},{"id":"90f342e1-1aaa-4e43-b092-39fda57ed11e","title":"ETW Logging Disabled For rpcrt4.dll","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-12-09","modified":"2023-08-17","description":"Detects changes to the \"ExtErrorInformation\" key in order to disable ETW logging for rpcrt4.dll","references":["http://redplait.blogspot.com/2020/07/whats-wrong-with-etw.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.defense-impairment","attack.t1112","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_rpcrt4_etw_tamper.yml","techniques":["T1112","T1685"],"cves":[]},{"id":"91903aba-1088-42ee-b680-d6d94fe002b0","title":"Windows Defender Submit Sample Feature Disabled","author":"Nasreddine Bencherchali (Nextron Systems)","status":"stable","level":"low","date":"2022-12-06","modified":null,"description":"Detects disabling of the \"Automatic Sample Submission\" feature of Windows Defender.","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide","https://bidouillesecurity.com/disable-windows-defender-in-powershell/#DisableAntiSpyware"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_config_change_sample_submission_consent.yml","techniques":["T1685"],"cves":[]},{"id":"92a974db-ab84-457f-9ec0-55db83d7a825","title":"Potential AMSI Bypass Using NULL Bits","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-01-04","modified":"2023-05-09","description":"Detects usage of special strings/null bits in order to potentially bypass AMSI functionalities","references":["https://github.com/r00t-3xp10it/hacking-material-books/blob/43cb1e1932c16ff1f58b755bc9ab6b096046853f/obfuscation/simple_obfuscation.md#amsi-bypass-using-null-bits-satoshi"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_amsi_null_bits_bypass.yml","techniques":["T1685"],"cves":[]},{"id":"93d298a1-d28f-47f1-a468-d971e7796679","title":"Disable Tamper Protection on Windows Defender","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-04","modified":"2023-08-17","description":"Detects disabling Windows Defender Tamper Protection","references":["https://www.tenforums.com/tutorials/123792-turn-off-tamper-protection-microsoft-defender-antivirus.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_disabled_tamper_protection_on_microsoft_defender.yml","techniques":["T1685"],"cves":[]},{"id":"9719a8aa-401c-41af-8108-ced7ec9cd75c","title":"Windows Defender Definition Files Removed","author":"frack113","status":"test","level":"high","date":"2021-07-07","modified":"2023-07-18","description":"Adversaries may disable security tools to avoid possible detection of their tools and activities by removing Windows Defender Definition Files","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://unit42.paloaltonetworks.com/unit42-gorgon-group-slithering-nation-state-cybercrime/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_mpcmdrun_remove_windows_defender_definition.yml","techniques":["T1685"],"cves":[]},{"id":"977ef627-4539-4875-adf4-ed8f780c4922","title":"Auditing Configuration Changes on Linux Host","author":"Mikhail Larin, oscd.community","status":"test","level":"high","date":"2019-10-25","modified":"2021-11-27","description":"Detect changes in auditd configuration files","references":["https://github.com/Neo23x0/auditd/blob/master/audit.rules","Self Experience"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/linux/auditd/path/lnx_auditd_auditing_config_change.yml","techniques":["T1685"],"cves":[]},{"id":"98054878-5eab-434c-85d4-72d4e5a3361b","title":"HackTool - EDRSilencer Execution - Filter Added","author":"Thodoris Polyzos (@SmoothDeploy)","status":"test","level":"high","date":"2024-01-29","modified":"2024-01-30","description":"Detects execution of EDRSilencer, a tool that abuses the Windows Filtering Platform (WFP) to block the outbound traffic of running EDR agents based on specific hardcoded filter names.\n","references":["https://github.com/netero1010/EDRSilencer"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/security/win_security_hktl_edr_silencer.yml","techniques":["T1685"],"cves":[]},{"id":"99c4658d-2c5e-4d87-828d-7c066ca537c3","title":"Disable-WindowsOptionalFeature Command PowerShell","author":"frack113","status":"test","level":"high","date":"2022-09-10","modified":null,"description":"Detect built in PowerShell cmdlet Disable-WindowsOptionalFeature, Deployment Image Servicing and Management tool.\nSimilar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/5b67c9b141fa3918017f8fa44f2f88f0b1ecb9e1/atomics/T1562.001/T1562.001.md","https://learn.microsoft.com/en-us/powershell/module/dism/disable-windowsoptionalfeature?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/powershell/powershell_script/posh_ps_disable_windows_optional_feature.yml","techniques":["T1685"],"cves":[]},{"id":"9b4e7c2a-3f6d-4a8b-b5e9-1c7d3f2e6a4b","title":"RedSun - Named Pipe Created","author":"Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost","status":"experimental","level":"critical","date":"2026-04-17","modified":null,"description":"Detects the creation of a named pipe with the hardcoded name \"REDSUN\".\nThe RedSun exploit tool uses a pipe with this name for synchronisation and command communication between its components during the Cloud Files API + oplock-based AV bypass and privilege escalation chain.\nRedSun creates the pipe as \\\\??\\pipe\\REDSUN.\nThe pipe server listens for the token-duplicated elevated process to connect and respond, completing the privilege escalation from user to SYSTEM.\nPresence of this pipe name indicates active or recent RedSun execution.\n","references":["https://github.com/Nightmare-Eclipse/RedSun/blob/7456cc8cf066f5e5fc6cdf7d3272a466ebd6b2f6/RedSun.cpp#L591","https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.privilege-escalation","attack.stealth","attack.defense-impairment","attack.t1055","attack.t1685","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/RedSun/pipe_created_win_exploit_redsun_named_pipe.yml","techniques":["T1055","T1685"],"cves":[]},{"id":"9d8f9bb8-01af-4e15-a3a2-349071530530","title":"Suspicious Path In Keyboard Layout IME File Registry Value","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-11-21","modified":null,"description":"Detects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message.\nBefore doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named \"Ime File\" with a DLL path.\nIMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.\n","references":["https://www.linkedin.com/pulse/guntior-story-advanced-bootkit-doesnt-rely-windows-disk-baranov-wue8e/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_ime_suspicious_paths.yml","techniques":["T1685"],"cves":[]},{"id":"9e8f6035-88bf-4a63-96b6-b17c0508257e","title":"Cisco Disabling Logging","author":"Austin Clark","status":"test","level":"high","date":"2019-08-11","modified":"2023-01-04","description":"Turn off logging locally or remote","references":["https://www.cisco.com/en/US/docs/ios/security/command/reference/sec_a2.pdf"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/network/cisco/aaa/cisco_cli_disable_logging.yml","techniques":["T1685"],"cves":[]},{"id":"9f4662ac-17ca-43aa-8f12-5d7b989d0101","title":"Tamper With Sophos AV Registry Keys","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-02","modified":"2023-08-17","description":"Detects tamper attempts to sophos av functionality via registry key modification","references":["https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_sophos_av_tamper.yml","techniques":["T1685"],"cves":[]},{"id":"9f5c1d59-33be-4e60-bcab-85d2f566effd","title":"Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-27","modified":null,"description":"Detects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace.\nThese DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll,\ndbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.\n","references":["https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html","https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpwritedump"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1003.001","attack.t1685"],"path":"rules/windows/process_access/proc_access_win_susp_dbgcore_dbghelp_load.yml","techniques":["T1003.001","T1685"],"cves":[]},{"id":"9f9f92ba-5300-43a4-b435-87d1ee571688","title":"Diamond Sleet APT Scheduled Task Creation - Registry","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-10-24","modified":null,"description":"Detects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability\n","references":["https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.defense-impairment","attack.t1685","detection.emerging-threats"],"path":"rules-emerging-threats/2023/TA/Diamond-Sleet/registry_event_apt_diamond_sleet_scheduled_task.yml","techniques":["T1685"],"cves":[]},{"id":"a1b2c3d4-e5f6-a7b8-c9d0-e1f2a3b4c5d6","title":"Disabling Windows Defender WMI Autologger Session via Reg.exe","author":"Matt Anderson (Huntress)","status":"experimental","level":"high","date":"2025-07-09","modified":null,"description":"Detects the use of reg.exe to disable the Event Tracing for Windows (ETW) Autologger session for Windows Defender API and Audit events.\nBy setting the 'Start' value to '0' for the 'DefenderApiLogger' or 'DefenderAuditLogger' session, an attacker can prevent these critical security events\nfrom being logged, effectively blinding monitoring tools that rely on this data. This is a powerful defense evasion technique.\n","references":["https://research.splunk.com/endpoint/76406a0f-f5e0-4167-8e1f-337fdc0f1b0c/","https://docs.microsoft.com/en-us/windows/win32/etw/configuring-and-starting-an-autologger-session","https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/","https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/","https://www.binarly.io/blog/design-issues-of-modern-edrs-bypassing-etw-based-solutions"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_disable_defender_wmi_autologger.yml","techniques":["T1685"],"cves":[]},{"id":"a238b5d0-ce2d-4414-a676-7a531b3d13d6","title":"ETW Trace Evasion Activity","author":"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community","status":"test","level":"high","date":"2019-03-22","modified":"2022-06-28","description":"Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.\n","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/wevtutil","https://abuse.io/lockergoga.txt","https://medium.com/palantir/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1070","attack.t1685","car.2016-04-002"],"path":"rules/windows/process_creation/proc_creation_win_susp_etw_trace_evasion.yml","techniques":["T1070","T1685"],"cves":[]},{"id":"a31eeaed-3fd5-478e-a8ba-e62c6b3f9ecc","title":"Raccine Uninstall","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-01-21","modified":"2022-10-09","description":"Detects commands that indicate a Raccine removal from an end system. Raccine is a free ransomware protection tool.","references":["https://github.com/Neo23x0/Raccine"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_susp_disable_raccine.yml","techniques":["T1685"],"cves":[]},{"id":"a34f79a3-8e5f-4cc3-b765-de00695452c2","title":"HackTool - PowerTool Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-11-29","modified":"2023-02-04","description":"Detects the execution of the tool PowerTool which has the ability to kill a process, delete its process file, unload drivers, and delete the driver files","references":["https://thedfirreport.com/2022/11/28/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware/","https://www.trendmicro.com/en_us/research/22/i/play-ransomware-s-attack-playbook-unmasks-it-as-another-hive-aff.html","https://twitter.com/gbti_sa/status/1249653895900602375?lang=en","https://www.softpedia.com/get/Antivirus/Removal-Tools/ithurricane-PowerTool.shtml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_hktl_powertool.yml","techniques":["T1685"],"cves":[]},{"id":"a3ab73f1-bd46-4319-8f06-4b20d0617886","title":"Windows Defender Exploit Guard Tamper","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-05","modified":"2022-12-06","description":"Detects when someone is adding or removing applications or folders from exploit guard \"ProtectedFolders\" or \"AllowedApplications\"\n","references":["https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/windows-10-controlled-folder-access-event-search/ba-p/2326088"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_config_change_exploit_guard_tamper.yml","techniques":["T1685"],"cves":[]},{"id":"a4c90ea1-2634-4ca0-adbb-35eae169b6fc","title":"ETW Logging Disabled In .NET Processes - Registry","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"high","date":"2020-06-05","modified":"2022-12-20","description":"Potential adversaries stopping ETW providers recording loaded .NET assemblies.","references":["https://twitter.com/_xpn_/status/1268712093928378368","https://social.msdn.microsoft.com/Forums/vstudio/en-US/0878832e-39d7-4eaf-8e16-a729c4c40975/what-can-i-use-e13c0d23ccbc4e12931bd9cc2eee27e4-for?forum=clr","https://github.com/dotnet/runtime/blob/ee2355c801d892f2894b0f7b14a20e6cc50e0e54/docs/design/coreclr/jit/viewing-jit-dumps.md#setting-configuration-variables","https://github.com/dotnet/runtime/blob/f62e93416a1799aecc6b0947adad55a0d9870732/src/coreclr/src/inc/clrconfigvalues.h#L35-L38","https://github.com/dotnet/runtime/blob/7abe42dc1123722ed385218268bb9fe04556e3d3/src/coreclr/src/inc/clrconfig.h#L33-L39","https://github.com/dotnet/runtime/search?p=1&q=COMPlus_&unscoped_q=COMPlus_","https://bunnyinside.com/?term=f71e8cb9c76a","http://managed670.rssing.com/chan-5590147/all_p1.html","https://github.com/dotnet/runtime/blob/4f9ae42d861fcb4be2fcd5d3d55d5f227d30e723/docs/coding-guidelines/clr-jit-coding-conventions.md#1412-disabling-code","https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.defense-impairment","attack.t1112","attack.t1685"],"path":"rules/windows/builtin/security/win_security_dot_net_etw_tamper.yml","techniques":["T1112","T1685"],"cves":[]},{"id":"a5c7a43f-6009-4a8c-80c5-32abf1c53ecc","title":"Microsoft Office Protected View Disabled","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-06-08","modified":"2023-08-17","description":"Detects changes to Microsoft Office protected view registry keys with which the attacker disables this feature.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://unit42.paloaltonetworks.com/unit42-gorgon-group-slithering-nation-state-cybercrime/","https://yoroi.company/research/cyber-criminal-espionage-operation-insists-on-italian-manufacturing/","https://admx.help/HKCU/software/policies/microsoft/office/16.0/excel/security/protectedview"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_office_disable_protected_view_features.yml","techniques":["T1685"],"cves":[]},{"id":"a607e1fe-74bf-4440-a3ec-b059b9103157","title":"AWS SecurityHub Findings Evasion","author":"Sittikorn S","status":"stable","level":"high","date":"2021-06-28","modified":null,"description":"Detects the modification of the findings on SecurityHub.","references":["https://docs.aws.amazon.com/cli/latest/reference/securityhub/"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/cloud/aws/cloudtrail/aws_securityhub_finding_evasion.yml","techniques":["T1685"],"cves":[]},{"id":"a7c3e5f2-8b1d-4e9a-b6c2-3d7f5e8a9b4c","title":"RedSun - TieringEngineService.exe Detected as EICAR Test File","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"critical","date":"2026-04-17","modified":null,"description":"Detects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe\ndropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present.\nThis covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based\nAV bypass/privilege escalation tool.\n\nRedSun works as follows:\n  1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\\RS-{GUID}\\\n  2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger\n     a Defender scan and remediation attempt\n  3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file\n  4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open\n  5. During the oplock break window, RedSun swaps the mount point (junction) to redirect\n     \\\\?\\C:\\Windows\\System32 to the attacker-controlled temp path\n  6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges\n","references":["https://github.com/Nightmare-Eclipse/RedSun/blob/7456cc8cf066f5e5fc6cdf7d3272a466ebd6b2f6/RedSun.cpp#L605","https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.stealth","attack.defense-impairment","attack.t1036.005","attack.t1685","attack.privilege-escalation","attack.t1055","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/RedSun/win_defender_exploit_redsun_tiering_engine_detected_as_eicar.yml","techniques":["T1036.005","T1685","T1055"],"cves":[]},{"id":"a7ee1722-c3c5-aeff-3212-c777e4733217","title":"Disable Windows Defender AV Security Monitoring","author":"ok @securonix invrep-de, oscd.community, frack113","status":"test","level":"high","date":"2020-10-12","modified":"2022-11-18","description":"Detects attackers attempting to disable Windows Defender using Powershell","references":["https://research.nccgroup.com/2020/06/23/wastedlocker-a-new-ransomware-variant-developed-by-the-evil-corp-group/","https://rvsec0n.wordpress.com/2020/01/24/malwares-that-bypass-windows-defender/","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_disable_defender_av_security_monitoring.yml","techniques":["T1685"],"cves":[]},{"id":"a982fc9c-6333-4ffb-a51d-addb04e8b529","title":"Windows Defender Exclusions Added - Registry","author":"Christian Burkard (Nextron Systems)","status":"test","level":"medium","date":"2021-07-06","modified":"2023-08-17","description":"Detects the Setting of Windows Defender Exclusions","references":["https://twitter.com/_nullbind/status/1204923340810543109"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_defender_exclusions.yml","techniques":["T1685"],"cves":[]},{"id":"aa37cbb0-da36-42cb-a90f-fdf216fc7467","title":"AMSI Disabled via Registry Modification","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-12-25","modified":null,"description":"Detects attempts to disable AMSI (Anti-Malware Scan Interface) by modifying the AmsiEnable registry value.\nAnti-Malware Scan Interface (AMSI) is a security feature in Windows that allows applications and services to integrate with anti-malware products for enhanced protection against malicious content.\nAdversaries may attempt to disable AMSI to evade detection by security software, allowing them to execute malicious scripts or code without being scanned.\n","references":["https://mostafayahiax.medium.com/hunting-for-amsi-bypassing-methods-9886dda0bf9d","https://docs.microsoft.com/en-us/windows/win32/amsi/antimalware-scan-interface-portal","https://www.mdsec.co.uk/2019/02/macros-and-more-with-sharpshooter-v2-0/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_amsi_disable.yml","techniques":["T1685"],"cves":[]},{"id":"acd74772-5f88-45c7-956b-6a7b36c294d2","title":"Removal Of SD Value to Hide Schedule Task - Registry","author":"Sittikorn S","status":"test","level":"medium","date":"2022-04-15","modified":"2025-10-25","description":"Remove SD (Security Descriptor) value in \\Schedule\\TaskCache\\Tree registry hive to hide schedule task. This technique is used by Tarrask malware","references":["https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_delete/registry_delete_schtasks_hide_task_via_sd_value_removal.yml","techniques":["T1685"],"cves":[]},{"id":"ae2bdd58-0681-48ac-be7f-58ab4e593458","title":"Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-05","modified":null,"description":"Detects attempts to remove Windows Defender configuration using the 'MpPreference' cmdlet","references":["https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/windows-10-controlled-folder-access-event-search/ba-p/2326088"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/powershell/powershell_script/posh_ps_tamper_windows_defender_rem_mp.yml","techniques":["T1685"],"cves":[]},{"id":"b28e58e4-2a72-4fae-bdee-0fbe904db642","title":"Windows Defender Real-time Protection Disabled","author":"Ján Trenčanský, frack113","status":"stable","level":"high","date":"2020-07-28","modified":"2023-11-22","description":"Detects disabling of Windows Defender Real-time Protection. As this event doesn't contain a lot of information on who initiated this action you might want to reduce it to a \"medium\" level if this occurs too many times in your environment\n","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide#event-id-5001","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://craigclouditpro.wordpress.com/2020/03/04/hunting-malicious-windows-defender-activity/"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_real_time_protection_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"b48492dc-c5ef-4572-8dff-32bc241c15c8","title":"Load Of RstrtMgr.DLL By A Suspicious Process","author":"Luc Génaux","status":"test","level":"high","date":"2023-11-28","modified":null,"description":"Detects the load of RstrtMgr DLL (Restart Manager) by a suspicious process.\nThis library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows.\nIt could also be used for anti-analysis purposes by shut downing specific processes.\n","references":["https://www.crowdstrike.com/blog/windows-restart-manager-part-1/","https://www.crowdstrike.com/blog/windows-restart-manager-part-2/","https://web.archive.org/web/20231221193106/https://www.swascan.com/cactus-ransomware-malware-analysis/","https://taiwan.postsen.com/business/88601/Hamas-hackers-use-data-destruction-software-BiBi-which-consumes-a-lot-of-processor-resources-to-wipe-Windows-computer-data--iThome.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.impact","attack.defense-impairment","attack.t1486","attack.t1685"],"path":"rules/windows/image_load/image_load_dll_rstrtmgr_suspicious_load.yml","techniques":["T1486","T1685"],"cves":[]},{"id":"b7e2a8d4-74bb-4b78-adc9-3f92af2d4829","title":"Reg Add Suspicious Paths","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-19","modified":"2022-10-10","description":"Detects when an adversary uses the reg.exe utility to add or modify new keys or subkeys","references":["https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1112/T1112.md","https://github.com/redcanaryco/atomic-red-team/blob/40b77d63808dd4f4eafb83949805636735a1fd15/atomics/T1562.001/T1562.001.md","https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.defense-impairment","attack.t1112","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_susp_paths.yml","techniques":["T1112","T1685"],"cves":[]},{"id":"b888e3f2-224d-4435-b00b-9dd66e9ea1f1","title":"Uncommon Extension In Keyboard Layout IME File Registry Value","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-11-21","modified":null,"description":"Detects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message.\nBefore doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named \"Ime File\" with a DLL path.\nIMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.\n","references":["https://www.linkedin.com/pulse/guntior-story-advanced-bootkit-doesnt-rely-windows-disk-baranov-wue8e/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_ime_non_default_extension.yml","techniques":["T1685"],"cves":[]},{"id":"b91e8d5e-0033-44fe-973f-b730316f23a1","title":"Bitbucket Secret Scanning Exempt Repository Added","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"high","date":"2024-02-25","modified":null,"description":"Detects when a repository is exempted from secret scanning feature.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_exempt_repository_detected.yml","techniques":["T1685"],"cves":[]},{"id":"b9e8c7d6-a5f4-4e3d-8b1a-9f0c8d7e6a5b","title":"Windows Defender Context Menu Removed","author":"Matt Anderson (Huntress)","status":"experimental","level":"high","date":"2025-07-09","modified":null,"description":"Detects the use of reg.exe or PowerShell to delete the Windows Defender context menu handler registry keys.\nThis action removes the \"Scan with Microsoft Defender\" option from the right-click menu for files, directories, and drives.\nAttackers may use this technique to hinder manual, on-demand scans and reduce the visibility of the security product.\n","references":["https://research.splunk.com/endpoint/395ed5fe-ad13-4366-9405-a228427bdd91/","https://winaero.com/how-to-delete-scan-with-windows-defender-from-context-menu-in-windows-10/","https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/","https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_defender_remove_context_menu.yml","techniques":["T1685"],"cves":[]},{"id":"bacf58c6-e199-4040-a94f-95dea0f1e45a","title":"Windows Filtering Platform Blocked Connection From EDR Agent Binary","author":"@gott_cyber","status":"test","level":"high","date":"2024-01-08","modified":null,"description":"Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents.\nAdversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.\n","references":["https://github.com/netero1010/EDRSilencer","https://github.com/amjcyber/EDRNoiseMaker","https://ghoulsec.medium.com/misc-series-4-forensics-on-edrsilencer-events-428b20b3f983"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/security/object_access/win_security_wfp_endpoint_agent_blocked.yml","techniques":["T1685"],"cves":[]},{"id":"bc275be9-0bec-4d77-8c8f-281a2df6710f","title":"Windows Defender Malware And PUA Scanning Disabled","author":"Ján Trenčanský, frack113","status":"stable","level":"high","date":"2020-07-28","modified":"2023-11-22","description":"Detects disabling of the Windows Defender feature of scanning for malware and other potentially unwanted software","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide#event-id-5010","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://craigclouditpro.wordpress.com/2020/03/04/hunting-malicious-windows-defender-activity/"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_malware_and_pua_scan_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"bc92ca75-cd42-4d61-9a37-9d5aa259c88b","title":"Win Defender Restored Quarantine File","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-12-06","modified":null,"description":"Detects the restoration of files from the defender quarantine","references":["https://learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_restored_quarantine_file.yml","techniques":["T1685"],"cves":[]},{"id":"bde30855-5c53-4c18-ae90-1ff79ebc9578","title":"Okta User Session Start Via An Anonymising Proxy Service","author":"kelnage","status":"test","level":"high","date":"2023-09-07","modified":"2026-04-27","description":"Detects when an Okta user session starts where the user is behind an anonymising proxy service.","references":["https://developer.okta.com/docs/reference/api/system-log/","https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection"],"logsource":{"product":"okta","service":"okta"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/identity/okta/okta_user_session_start_via_anonymised_proxy.yml","techniques":["T1685"],"cves":[]},{"id":"bf4fc428-dcc3-4bbd-99fe-2422aeee2544","title":"ETW Logging Disabled In .NET Processes - Sysmon Registry","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"high","date":"2020-06-05","modified":"2023-08-17","description":"Potential adversaries stopping ETW providers recording loaded .NET assemblies.","references":["https://twitter.com/_xpn_/status/1268712093928378368","https://social.msdn.microsoft.com/Forums/vstudio/en-US/0878832e-39d7-4eaf-8e16-a729c4c40975/what-can-i-use-e13c0d23ccbc4e12931bd9cc2eee27e4-for?forum=clr","https://github.com/dotnet/runtime/blob/ee2355c801d892f2894b0f7b14a20e6cc50e0e54/docs/design/coreclr/jit/viewing-jit-dumps.md#setting-configuration-variables","https://github.com/dotnet/runtime/blob/f62e93416a1799aecc6b0947adad55a0d9870732/src/coreclr/src/inc/clrconfigvalues.h#L35-L38","https://github.com/dotnet/runtime/blob/7abe42dc1123722ed385218268bb9fe04556e3d3/src/coreclr/src/inc/clrconfig.h#L33-L39","https://github.com/dotnet/runtime/search?p=1&q=COMPlus_&unscoped_q=COMPlus_","https://bunnyinside.com/?term=f71e8cb9c76a","http://managed670.rssing.com/chan-5590147/all_p1.html","https://github.com/dotnet/runtime/blob/4f9ae42d861fcb4be2fcd5d3d55d5f227d30e723/docs/coding-guidelines/clr-jit-coding-conventions.md#1412-disabling-code","https://blog.xpnsec.com/hiding-your-dotnet-complus-etwenabled/","https://i.blackhat.com/EU-21/Wednesday/EU-21-Teodorescu-Veni-No-Vidi-No-Vici-Attacks-On-ETW-Blind-EDRs.pdf"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.defense-impairment","attack.t1112","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_dot_net_etw_tamper.yml","techniques":["T1112","T1685"],"cves":[]},{"id":"bf9e1387-b040-4393-9851-1598f8ecfae9","title":"Disable Exploit Guard Network Protection on Windows Defender","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-04","modified":"2023-08-17","description":"Detects disabling Windows Defender Exploit Guard Network Protection","references":["https://www.tenforums.com/tutorials/105533-enable-disable-windows-defender-exploit-protection-settings.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_disabled_exploit_guard_net_protection_on_ms_defender.yml","techniques":["T1685"],"cves":[]},{"id":"c0514f28-fdae-42df-b886-06e2b2bc5b37","title":"Service Startup Type Change Via Wmic.EXE","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-04-27","modified":null,"description":"Detects changes to service startup type to 'disabled' or 'manual' using the WMIC command-line utility.\n","references":["https://blog.talosintelligence.com/uncovering-qilin-attack-methods-exposed-through-multiple-cases/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.defense-impairment","attack.t1047","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_wmic_service_startup_change.yml","techniques":["T1047","T1685"],"cves":[]},{"id":"c1344fa2-323b-4d2e-9176-84b4d4821c88","title":"Windows Defender Exclusions Added - PowerShell","author":"Tim Rauch, Elastic (idea)","status":"test","level":"medium","date":"2022-09-16","modified":"2022-11-26","description":"Detects modifications to the Windows Defender configuration settings using PowerShell to add exclusions","references":["https://www.elastic.co/guide/en/security/current/windows-defender-exclusions-added-via-powershell.html"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685","attack.execution","attack.t1059"],"path":"rules/windows/powershell/powershell_script/posh_ps_win_defender_exclusions_added.yml","techniques":["T1685","T1059"],"cves":[]},{"id":"c17d47b7-dcd6-4109-87eb-d1817bd4cbc9","title":"Windows Credential Guard Registry Tampering Via CommandLine","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-12-26","modified":null,"description":"Detects attempts to add, modify, or delete Windows Credential Guard related registry keys or values via command line tools such as Reg.exe or PowerShell.\nCredential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them.\nAdversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.\nThe rule matches suspicious command lines that target DeviceGuard or LSA registry paths and manipulate keys like EnableVirtualizationBasedSecurity, RequirePlatformSecurityFeatures, or LsaCfgFlags.\nSuch activity may indicate an attempt to disable or tamper with Credential Guard, potentially exposing sensitive credentials for misuse.\n","references":["https://woshub.com/disable-credential-guard-windows/","https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_credential_guard_registry_tampering.yml","techniques":["T1685"],"cves":[]},{"id":"c2c76b77-32be-4d1f-82c9-7e544bdfe0eb","title":"Potential Suspicious Activity Using SeCEdit","author":"Janantha Marasinghe","status":"test","level":"medium","date":"2022-11-18","modified":"2022-12-30","description":"Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy","references":["https://blueteamops.medium.com/secedit-and-i-know-it-595056dee53d","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/secedit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.discovery","attack.persistence","attack.credential-access","attack.privilege-escalation","attack.execution","attack.stealth","attack.defense-impairment","attack.t1685.001","attack.t1547.001","attack.t1505.005","attack.t1556.002","attack.t1685","attack.t1574.007","attack.t1564.002","attack.t1546.008","attack.t1546.007","attack.t1547.014","attack.t1547.010","attack.t1547.002","attack.t1557","attack.t1082"],"path":"rules/windows/process_creation/proc_creation_win_secedit_execution.yml","techniques":["T1685.001","T1547.001","T1505.005","T1556.002","T1685","T1574.007","T1564.002","T1546.008","T1546.007","T1547.014","T1547.010","T1547.002","T1557","T1082"],"cves":[]},{"id":"c443012c-7928-43bf-ac20-7eda5efe61ad","title":"Suspicious Uninstall of Windows Defender Feature via PowerShell","author":"yxinmiracle","status":"experimental","level":"high","date":"2025-08-22","modified":null,"description":"Detects the use of PowerShell with Uninstall-WindowsFeature or Remove-WindowsFeature cmdlets to disable or remove the Windows Defender GUI feature, a common technique used by adversaries to evade defenses.\n","references":["https://learn.microsoft.com/en-us/powershell/module/microsoft.windows.servermanager.migration/uninstall-windowsfeature","https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_uninstall_defender_feature.yml","techniques":["T1685"],"cves":[]},{"id":"c598cc0c-9e70-4852-b9eb-8921af79f598","title":"Hacktool - EDR-Freeze Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-09-24","modified":"2025-11-27","description":"Detects execution of EDR-Freeze, a tool that exploits the MiniDumpWriteDump function and WerFaultSecure.exe to suspend EDR and Antivirus processes on Windows.\nEDR-Freeze leverages a race-condition attack to put security processes into a dormant state by suspending WerFaultSecure at the moment it freezes the target process.\nThis technique does not require kernel-level exploits or BYOVD, but instead abuses user-mode functionality to temporarily disable monitoring by EDR or Antimalware solutions.\n","references":["https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html","https://github.com/TwoSevenOneT/EDR-Freeze"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_hktl_edr_freeze.yml","techniques":["T1685"],"cves":[]},{"id":"c6fb44c6-71f5-49e6-9462-1425d328aee3","title":"Powershell Base64 Encoded MpPreference Cmdlet","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-04","modified":"2023-01-30","description":"Detects base64 encoded \"MpPreference\" PowerShell cmdlet code that tries to modifies or tamper with Windows Defender AV","references":["https://learn.microsoft.com/en-us/defender-endpoint/configure-process-opened-file-exclusions-microsoft-defender-antivirus","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://twitter.com/AdamTheAnalyst/status/1483497517119590403"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_base64_mppreference.yml","techniques":["T1685"],"cves":[]},{"id":"c830f15d-6f6e-430f-8074-6f73d6807841","title":"Logging Configuration Changes on Linux Host","author":"Mikhail Larin, oscd.community","status":"test","level":"high","date":"2019-10-25","modified":"2021-11-27","description":"Detect changes of syslog daemons configuration files","references":["self experience"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/linux/auditd/path/lnx_auditd_logging_config_change.yml","techniques":["T1685"],"cves":[]},{"id":"ccd55945-badd-4bae-936b-823a735d37dd","title":"Github Push Protection Disabled","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"high","date":"2024-03-07","modified":null,"description":"Detects if the push protection feature is disabled for an organization, enterprise, repositories or custom pattern rules.","references":["https://docs.github.com/en/enterprise-cloud@latest/code-security/secret-scanning/push-protection-for-repositories-and-organizations","https://thehackernews.com/2024/03/github-rolls-out-default-secret.html"],"logsource":{"product":"github","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/github/audit/github_push_protection_disabled.yml","techniques":["T1685"],"cves":[]},{"id":"cd1f961e-0b96-436b-b7c6-38da4583ec00","title":"Suspicious Windows Trace ETW Session Tamper Via Logman.EXE","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-02-11","modified":"2023-02-21","description":"Detects the execution of \"logman\" utility in order to disable or delete Windows trace sessions","references":["https://twitter.com/0gtweet/status/1359039665232306183?s=21","https://ss64.com/nt/logman.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685","attack.t1685.005"],"path":"rules/windows/process_creation/proc_creation_win_logman_disable_eventlog.yml","techniques":["T1685","T1685.005"],"cves":[]},{"id":"ce72ef99-22f1-43d4-8695-419dcb5d9330","title":"Suspicious Windows Service Tampering","author":"Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems)","status":"test","level":"high","date":"2022-09-01","modified":"2025-08-27","description":"Detects the usage of binaries such as 'net', 'sc' or 'powershell' in order to stop, pause, disable or delete critical or important Windows services such as AV, Backup, etc. As seen being used in some ransomware scripts\n","references":["https://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus/Genshin%20Impact%20Figure%2010.jpg","https://www.trellix.com/en-sg/about/newsroom/stories/threat-labs/lockergoga-ransomware-family-used-in-targeted-attacks.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/","https://www.virustotal.com/gui/file/38283b775552da8981452941ea74191aa0d203edd3f61fb2dee7b0aea3514955","https://learn.microsoft.com/en-us/windows/win32/cimwin32prov/delete-method-in-class-win32-service"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.impact","attack.defense-impairment","attack.t1489","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_susp_service_tamper.yml","techniques":["T1489","T1685"],"cves":[]},{"id":"d2656e78-c069-4571-8220-9e0ab5913f19","title":"AWS GuardDuty Detector Deleted Or Updated","author":"suktech24","status":"experimental","level":"high","date":"2025-11-27","modified":null,"description":"Detects successful deletion or disabling of an AWS GuardDuty detector, possibly by an attacker trying to avoid detection of its malicious activities.\nUpon deletion, GuardDuty stops monitoring the environment and all existing findings are lost.\nVerify with the user identity that this activity is legitimate.\n","references":["https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeleteDetector.html","https://docs.aws.amazon.com/guardduty/latest/APIReference/API_UpdateDetector.html","https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_suspend-disable.html","https://docs.datadoghq.com/security/default_rules/719-39f-9cd/","https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/ensure-aws-guardduty-detector-is-enabled","https://docs.stellarcyber.ai/5.2.x/Using/ML/Alert-Rule-Based-Potentially_Malicious_AWS_Activity.html","https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Amazon%20Web%20Services/Analytic%20Rules/AWS_GuardDutyDisabled.yaml","https://github.com/elastic/detection-rules/blob/main/rules/integrations/aws/defense_evasion_guardduty_detector_deletion.toml","https://help.fortinet.com/fsiem/Public_Resource_Access/7_4_0/rules/PH_RULE_AWS_GuardDuty_Detector_Deletion.htm","https://research.splunk.com/sources/5d8bd475-c8bc-4447-b27f-efa508728b90/","https://suktech24.com/2025/07/17/aws-threat-detection-rule-guardduty-detector-disabled-or-suspended/","https://www.atomicredteam.io/atomic-red-team/atomics/T156001#atomic-test-46---aws---guardduty-suspension-or-deletion"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685","attack.t1685.002"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_guardduty_detector_deleted_or_updated.yml","techniques":["T1685","T1685.002"],"cves":[]},{"id":"d3abac66-f11c-4ed0-8acb-50cc29c97eed","title":"NetNTLM Downgrade Attack","author":"Florian Roth (Nextron Systems), wagga","status":"test","level":"high","date":"2018-03-20","modified":"2022-10-09","description":"Detects NetNTLM downgrade attack","references":["https://www.optiv.com/blog/post-exploitation-using-netntlm-downgrade-attacks"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.defense-impairment","attack.t1685","attack.t1112"],"path":"rules/windows/builtin/security/win_security_net_ntlm_downgrade.yml","techniques":["T1685","T1112"],"cves":[]},{"id":"d526c60a-e236-4011-b165-831ffa52ab70","title":"Windows Vulnerable Driver Blocklist Disabled","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-01-26","modified":null,"description":"Detects when the Windows Vulnerable Driver Blocklist is set to disabled. This setting is crucial for preventing the loading of known vulnerable drivers,\nand its modification may indicate an attempt to bypass security controls. It is often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers,\nparticularly in scenarios involving Endpoint Detection and Response (EDR) bypass techniques.\nThis rule applies to systems that support the Vulnerable Driver Blocklist feature, including Windows 10 version 1903 and later, and Windows Server 2022 and later.\nNote that this change will require a reboot to take effect, and this rule only detects the registry modification action.\n","references":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules","https://www.sophos.com/en-us/blog/sharpening-the-knife-gold-blades-strategic-evolution","https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_vulnerable_driver_blocklist_disable.yml","techniques":["T1685"],"cves":[]},{"id":"d645ef86-2396-48a1-a2b6-b629ca3f57ff","title":"Windows Credential Guard Related Registry Value Deleted - Registry","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-12-26","modified":null,"description":"Detects attempts to disable Windows Credential Guard by deleting registry values. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them.\nAdversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.\n","references":["https://github.com/DambergC/SaveFolder/blob/90e945eba80fae85f2d54b4616e05a44ec90c500/Cygate%20Installation%20tool%206.22/Script/OSD/OSDeployment-CredentialGuardDisable.ps1#L50","https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/configure"],"logsource":{"product":"windows","category":"registry_delete"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_delete/registry_delete_disable_credential_guard.yml","techniques":["T1685"],"cves":[]},{"id":"d67572a0-e2ec-45d6-b8db-c100d14b8ef2","title":"NetNTLM Downgrade Attack - Registry","author":"Florian Roth (Nextron Systems), wagga, Nasreddine Bencherchali (Splunk STRT)","status":"test","level":"high","date":"2018-03-20","modified":"2024-12-03","description":"Detects NetNTLM downgrade attack","references":["https://web.archive.org/web/20171113231705/https://www.optiv.com/blog/post-exploitation-using-netntlm-downgrade-attacks","https://www.ultimatewindowssecurity.com/wiki/page.aspx?spid=NSrpcservers"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.persistence","attack.defense-impairment","attack.t1685","attack.t1112"],"path":"rules/windows/registry/registry_event/registry_event_net_ntlm_downgrade.yml","techniques":["T1685","T1112"],"cves":[]},{"id":"d7662ff6-9e97-4596-a61d-9839e32dee8d","title":"Add SafeBoot Keys Via Reg Utility","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-02","modified":"2024-03-19","description":"Detects execution of \"reg.exe\" commands with the \"add\" or \"copy\" flags on safe boot registry keys. Often used by attacker to allow the ransomware to work in safe mode as some security products do not","references":["https://redacted.com/blog/bianlian-ransomware-gang-gives-it-a-go/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_add_safeboot.yml","techniques":["T1685"],"cves":[]},{"id":"da92713f-ca2d-4fab-8320-098013d3f43a","title":"Windows Defender Disabled Via SystemSettingsAdminFlows.EXE","author":"Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-07-01","modified":null,"description":"Detects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender.\nSystemSettingsAdminFlows.exe is a legitimate Windows component used for administrative configuration tasks.\nHowever, attackers may abuse it to disable Windows Defender as part of their attack chain, especially in the context of ransomware or other malware campaigns.\n","references":["https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/","https://www.huntress.com/blog/lolbin-to-inc-ransomware"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_systemsettingsadminflows_defender_disable.yml","techniques":["T1685"],"cves":[]},{"id":"dd80db93-6ec2-4f4c-a017-ad40da6ffe81","title":"Windows Defender Real-Time Protection Failure/Restart","author":"Nasreddine Bencherchali (Nextron Systems), Christopher Peacock '@securepeacock' (Update)","status":"stable","level":"medium","date":"2023-03-28","modified":"2023-05-05","description":"Detects issues with Windows Defender Real-Time Protection features","references":["Internal Research","https://www.microsoft.com/en-us/security/blog/2023/04/11/guidance-for-investigating-attacks-using-cve-2022-21894-the-blacklotus-campaign/","https://gist.github.com/nasbench/33732d6705cbdc712fae356f07666346"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/windefend/win_defender_real_time_protection_errors.yml","techniques":["T1685"],"cves":[]},{"id":"de25eeb8-3655-4643-ac3a-b662d3f26b6b","title":"Disable Or Stop Services","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-09-15","modified":"2025-03-18","description":"Detects the usage of utilities such as 'systemctl', 'service'...etc to stop or disable tools and services on Linux systems.\nAttackers may stop or disable security tools and services to evade detection, maintain persistence, or disrupt system operations.\n","references":["https://www.trendmicro.com/pl_pl/research/20/i/the-evolution-of-malicious-shell-scripts.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685","attack.impact","attack.t1489"],"path":"rules/linux/process_creation/proc_creation_lnx_services_stop_and_disable.yml","techniques":["T1685","T1489"],"cves":[]},{"id":"dee4af55-1f22-4e1d-a9d2-4bdc7ecb472a","title":"Disabled Volume Snapshots","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-01-28","modified":"2023-12-15","description":"Detects commands that temporarily turn off Volume Snapshots","references":["https://twitter.com/0gtweet/status/1354766164166115331"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_volsnap_disable.yml","techniques":["T1685"],"cves":[]},{"id":"e0d6c087-2d1c-47fd-8799-3904103c5a98","title":"AMSI Bypass Pattern Assembly GetType","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-11-09","modified":null,"description":"Detects code fragments found in small and obfuscated AMSI bypass PowerShell scripts","references":["https://www.mdsec.co.uk/2018/06/exploring-powershell-amsi-and-logging-evasion/","https://twitter.com/cyb3rops/status/1588574518057979905?s=20&t=A7hh93ONM7ni1Rj1jO5OaA"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685","attack.execution"],"path":"rules/windows/powershell/powershell_script/posh_ps_amsi_bypass_pattern_nov22.yml","techniques":["T1685"],"cves":[]},{"id":"e16cf0f0-ee88-4901-bd0b-4c8d13d9ee05","title":"Bitbucket Global Secret Scanning Rule Deleted","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects Bitbucket global secret scanning rule deletion activity.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/bitbucket/audit/bitbucket_audit_global_secret_scanning_rule_deleted.yml","techniques":["T1685"],"cves":[]},{"id":"e1aa95de-610a-427d-b9e7-9b46cfafbe6a","title":"Windows Defender Service Disabled - Registry","author":"Ján Trenčanský, frack113, AlertIQ, Nasreddine Bencherchali","status":"test","level":"high","date":"2022-08-01","modified":"2024-03-25","description":"Detects when an attacker or tool disables the  Windows Defender service (WinDefend) via the registry","references":["https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/","https://gist.github.com/anadr/7465a9fde63d41341136949f14c21105"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_disable_windows_defender_service.yml","techniques":["T1685"],"cves":[]},{"id":"e497a24e-9345-4a62-9803-b06d7d7cb132","title":"ASLR Disabled Via Sysctl or Direct Syscall - Linux","author":"Milad Cheraghi","status":"experimental","level":"high","date":"2025-05-26","modified":"2025-12-05","description":"Detects actions that disable Address Space Layout Randomization (ASLR) in Linux, including:\n  - Use of the `personality` syscall with the ADDR_NO_RANDOMIZE flag (0x0040000)\n  - Modification of the /proc/sys/kernel/randomize_va_space file\n  - Execution of the `sysctl` command to set `kernel.randomize_va_space=0`\nDisabling ASLR is often used by attackers during exploit development or to bypass memory protection mechanisms.\nA successful use of these methods can reduce the effectiveness of ASLR and make memory corruption attacks more reliable.\n","references":["https://github.com/CheraghiMilad/bypass-Neo23x0-auditd-config/blob/f1c478a37911a5447d5ffcd580f22b167bf3df14/personality-syscall/README.md","https://man7.org/linux/man-pages/man2/personality.2.html","https://manual.cs50.io/2/personality","https://linux-audit.com/linux-aslr-and-kernelrandomize_va_space-setting/"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.stealth","attack.defense-impairment","attack.t1685","attack.t1055.009"],"path":"rules/linux/auditd/lnx_auditd_disable_aslr_protection.yml","techniques":["T1685","T1055.009"],"cves":[]},{"id":"e9c8808f-4cfb-4ba9-97d4-e5f3beaa244d","title":"Windows Defender Exclusion Registry Key - Write Access Requested","author":"@BarryShooshooga, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2019-10-26","modified":"2023-11-11","description":"Detects write access requests to the Windows Defender exclusions registry keys. This could be an indication of an attacker trying to request a handle or access the object to write new exclusions in order to bypass security.\n","references":["https://www.bleepingcomputer.com/news/security/gootkit-malware-bypasses-windows-defender-by-setting-path-exclusions/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/security/win_security_windows_defender_exclusions_write_access.yml","techniques":["T1685"],"cves":[]},{"id":"eb2d07d4-49cb-4523-801a-da002df36602","title":"HackTool - EDRSilencer Execution","author":"@gott_cyber","status":"test","level":"high","date":"2024-01-02","modified":null,"description":"Detects the execution of EDRSilencer, a tool that leverages Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server based on PE metadata information.\n","references":["https://github.com/netero1010/EDRSilencer"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_hktl_edrsilencer.yml","techniques":["T1685"],"cves":[]},{"id":"ec19ebab-72dc-40e1-9728-4c0b805d722c","title":"Tamper Windows Defender - PSClassic","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-06-07","modified":"2024-01-02","description":"Attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md"],"logsource":{"product":"windows","category":"ps_classic_provider_start"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/powershell/powershell_classic/posh_pc_tamper_windows_defender_set_mp.yml","techniques":["T1685"],"cves":[]},{"id":"ef0ff092-a24a-4fbc-beea-06c08d53e085","title":"Cisco Dot1x Disabled","author":"Luc Génaux","status":"experimental","level":"medium","date":"2026-04-28","modified":null,"description":"Detects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface.\nDisabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network.\nThis activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.\n","references":["https://www.cisco.com/en/US/docs/ios-xml/ios/san/command/san-xe-3se-3850-cr-book_chapter_00.html#wp3394428680","https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-xe-3se-3850-cr-book/sec-a1-xe-3se-3850-cr-book_chapter_010.html#wp3502072400","https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960/software/release/12-2_53_se/command/reference/2960ComRef/cli1.html#47220"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.persistence","attack.credential-access","attack.defense-impairment","attack.t1685","attack.t1556.004"],"path":"rules/network/cisco/aaa/cisco_cli_dot1x_disabled.yml","techniques":["T1685","T1556.004"],"cves":[]},{"id":"f0f7be61-9cf5-43be-9836-99d6ef448a18","title":"Uninstall Crowdstrike Falcon Sensor","author":"frack113","status":"test","level":"high","date":"2021-07-12","modified":"2023-03-09","description":"Adversaries may disable security tools to avoid possible detection of their tools and activities by uninstalling Crowdstrike Falcon","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_uninstall_crowdstrike_falcon.yml","techniques":["T1685"],"cves":[]},{"id":"f2485272-a156-4773-82d7-1d178bc4905b","title":"Suspicious Service Installed","author":"xknow (@xknow_infosec), xorxes (@xor_xes)","status":"test","level":"medium","date":"2019-04-08","modified":"2026-06-29","description":"Detects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders.\nBoth services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)\n","references":["https://web.archive.org/web/20200419024230/https://blog.dylan.codes/evading-sysmon-and-windows-event-logging/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_susp_service_installed.yml","techniques":["T1685"],"cves":[]},{"id":"f44800ac-38ec-471f-936e-3fa7d9c53100","title":"PUA - CleanWipe Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-12-18","modified":"2023-02-14","description":"Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.","references":["https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Other/CleanWipe"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_pua_cleanwipe.yml","techniques":["T1685"],"cves":[]},{"id":"f63508a0-c809-4435-b3be-ed819394d612","title":"Potential Privileged System Service Operation - SeLoadDriverPrivilege","author":"xknow (@xknow_infosec), xorxes (@xor_xes)","status":"test","level":"medium","date":"2019-04-08","modified":"2026-06-29","description":"Detects the usage of the 'SeLoadDriverPrivilege' privilege. This privilege is required to load or unload a device driver.\nWith this privilege, the user can dynamically load and unload device drivers or other code in to kernel mode.\nThis user right does not apply to Plug and Play device drivers.\nIf you exclude privileged users/admins and processes, which are allowed to do so, you are maybe left with bad programs trying to load malicious kernel drivers.\nThis will detect Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs) and the usage of Sysinternals and various other tools. So you have to work with a whitelist to find the bad stuff.\n","references":["https://web.archive.org/web/20230331181619/https://blog.dylan.codes/evading-sysmon-and-windows-event-logging/","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4673"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/security/win_security_user_driver_loaded.yml","techniques":["T1685"],"cves":[]},{"id":"f6de9536-0441-4b3f-a646-f4e00f300ffd","title":"Weak Encryption Enabled and Kerberoast","author":"@neu5ron","status":"test","level":"high","date":"2017-07-30","modified":"2021-11-27","description":"Detects scenario where weak encryption is enabled for a user profile which could be used for hash/password cracking.","references":["https://adsecurity.org/?p=2053","https://blog.harmj0y.net/redteaming/another-word-on-delegation/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/builtin/security/win_security_alert_enable_weak_encryption.yml","techniques":["T1685"],"cves":[]},{"id":"fa2559c8-1197-471d-9cdd-05a0273d4522","title":"Potential AMSI Bypass Script Using NULL Bits","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-01-04","modified":"2023-05-09","description":"Detects usage of special strings/null bits in order to potentially bypass AMSI functionalities","references":["https://github.com/r00t-3xp10it/hacking-material-books/blob/43cb1e1932c16ff1f58b755bc9ab6b096046853f/obfuscation/simple_obfuscation.md#amsi-bypass-using-null-bits-satoshi"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/powershell/powershell_script/posh_ps_amsi_null_bits_bypass.yml","techniques":["T1685"],"cves":[]},{"id":"fb50eb7a-5ab1-43ae-bcc9-091818cb8424","title":"Disabled IE Security Features","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-06-19","modified":"2021-11-27","description":"Detects command lines that indicate unwanted modifications to registry keys that disable important Internet Explorer security features","references":["https://unit42.paloaltonetworks.com/operation-ke3chang-resurfaces-with-new-tidepool-malware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_powershell_disable_ie_features.yml","techniques":["T1685"],"cves":[]},{"id":"fc0e89b5-adb0-43c1-b749-c12a10ec37de","title":"SafeBoot Registry Key Deleted Via Reg.EXE","author":"Nasreddine Bencherchali (Nextron Systems), Tim Shelton","status":"test","level":"high","date":"2022-08-08","modified":"2023-02-04","description":"Detects execution of \"reg.exe\" commands with the \"delete\" flag on safe boot registry keys. Often used by attacker to prevent safeboot execution of security products","references":["https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_reg_delete_safeboot.yml","techniques":["T1685"],"cves":[]},{"id":"fcddca7c-b9c0-4ddf-98da-e1e2d18b0157","title":"Disabled Windows Defender Eventlog","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-07-04","modified":"2023-08-17","description":"Detects the disabling of the Windows Defender eventlog as seen in relation to Lockbit 3.0 infections","references":["https://twitter.com/WhichbufferArda/status/1543900539280293889/photo/2"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/windows/registry/registry_set/registry_set_disabled_microsoft_defender_eventlog.yml","techniques":["T1685"],"cves":[]},{"id":"fe513c69-734c-4d4a-8548-ac5f609be82b","title":"Google Cloud Firewall Modified or Deleted","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-13","modified":"2022-10-09","description":"Detects  when a firewall rule is modified or deleted in Google Cloud Platform (GCP).","references":["https://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging","https://developers.google.com/resources/api-libraries/documentation/compute/v1/java/latest/com/google/api/services/compute/Compute.Firewalls.html"],"logsource":{"product":"gcp","service":"gcp.audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/cloud/gcp/audit/gcp_firewall_rule_modified_or_deleted.yml","techniques":["T1685"],"cves":[]},{"id":"ff39f1a6-84ac-476f-a1af-37fcdf53d7c0","title":"Disable Security Tools","author":"Daniil Yugoslavskiy, oscd.community","status":"test","level":"medium","date":"2020-10-19","modified":"2021-11-27","description":"Detects disabling security tools","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/macos/process_creation/proc_creation_macos_disable_security_tools.yml","techniques":["T1685"],"cves":[]},{"id":"ff91e3f0-ad15-459f-9a85-1556390c138d","title":"Bitbucket Secret Scanning Rule Deleted","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"low","date":"2024-02-25","modified":null,"description":"Detects when secret scanning rule is deleted for the project or repository.","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html","https://confluence.atlassian.com/bitbucketserver/secret-scanning-1157471613.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.defense-impairment","attack.t1685"],"path":"rules/application/bitbucket/audit/bitbucket_audit_secret_scanning_rule_deleted.yml","techniques":["T1685"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}