{
  "node_id": "mitre-attack-t1685-disable-or-modify-tools",
  "title": "MITRE ATT&CK T1685: Disable or Modify Tools (Enterprise Tactic TA0112 - Defense Impairment)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-06",
  "bluf": "MITRE ATT&CK T1685 (Disable or Modify Tools) is an Enterprise Defense Impairment technique. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments. In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing fo... Affected platforms: Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows. ATT&CK-mapped mitigations: M1018 User Account Management, M1047 Audit, M1022 Restrict File and Directory Permissions, M1042 Disable or Remove Feature or Program, M1054 Software Configuration, M1038 Execution Prevention, M1024 Restrict Registry Permissions.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 11
}