T1562.001 Disable or Modify Tools Mappings

Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take the many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information.

Adversaries may also tamper with artifacts deployed and utilized by security tools. Security tools may make dynamic changes to system components in order to maintain visibility into specific events. For example, security products may load their own modules and/or modify those loaded by processes to facilitate data collection. Similar to Indicator Blocking, adversaries may unhook or otherwise modify these features added by tools (especially those that exist in userland or are otherwise potentially accessible to adversaries) to avoid detection.(Citation: OutFlank System Calls)(Citation: MDSec System Calls)

View in MITRE ATT&CK®

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
AC-2 Account Management Protects T1562.001 Disable or Modify Tools
AC-3 Access Enforcement Protects T1562.001 Disable or Modify Tools
AC-5 Separation of Duties Protects T1562.001 Disable or Modify Tools
AC-6 Least Privilege Protects T1562.001 Disable or Modify Tools
CA-7 Continuous Monitoring Protects T1562.001 Disable or Modify Tools
CM-2 Baseline Configuration Protects T1562.001 Disable or Modify Tools
CM-5 Access Restrictions for Change Protects T1562.001 Disable or Modify Tools
CM-6 Configuration Settings Protects T1562.001 Disable or Modify Tools
CM-7 Least Functionality Protects T1562.001 Disable or Modify Tools
IA-2 Identification and Authentication (organizational Users) Protects T1562.001 Disable or Modify Tools
SI-3 Malicious Code Protection Protects T1562.001 Disable or Modify Tools
SI-4 System Monitoring Protects T1562.001 Disable or Modify Tools
SI-7 Software, Firmware, and Information Integrity Protects T1562.001 Disable or Modify Tools