Compliance Node Overview
MITRE ATT&CK T1622 (Debugger Evasion) is an Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads. Debugger evasion may include changing behaviors based on the results of the checks for the presence of artifacts indicative of a debugged environment. Similar to Virtualization/Sandbox Evasion, if the adversary detects a debugger, they may alter their malware to disengage from the victim or conceal the core functions of the implant. Affected platforms: Windows, Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, CA-07, CM-02, CM-06, CM-07, CM-08, SC-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1622/
SHA-256 integrity: 021fce4510cb473a82f09a3902b1a9b3dcd0ab8a79fcaf55b6f918a054d253c5
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1622: Debugger Evasion (https://attack.mitre.org/techniques/T1622/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access