What MITRE ATT&CK T1685.003: Modify or Spoof Tool UI (Enterprise Tactic TA0112 - Defense Impairment) requires
MITRE ATT&CK T1685.003 (Modify or Spoof Tool UI) is an Enterprise Defense Impairment technique. Adversaries may spoof or manipulate security tool user interfaces (UIs) to falsely indicate tools are functioning normally and delay detection and response. Adversaries may present misleading or falsified security tool interfaces (UIs) that display normal or healthy status indicators, even when underlying security tools have been disabled, degraded, or otherwise tampered with. Security tools typically provide visibility into system health, alerting, and operational status; by misrepresenting this information, adversaries can undermine defender trust in these signals and obscure the true security posture of the system. This behavior is often used in conjunction with efforts to disable or modify tools, where adversaries first impair the functionality of defenses (e.g., EDR, logging agents) a... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1685. ATT&CK-mapped mitigations: M1038 Execution Prevention.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1685/003/
SHA-256 integrity: 7815ddf650e1c3b32f98f7e6c9e1f368771a59365b2245e8ff4be745f9d902e2
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1685.003: Modify or Spoof Tool UI (https://attack.mitre.org/techniques/T1685/003/)
- MITRE ATT&CK Tactic TA0112: Defense Impairment (https://attack.mitre.org/tactics/TA0112/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1685-003-modify-or-spoof-tool-ui.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1685-003-modify-or-spoof-tool-ui.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1685-003-modify-or-spoof-tool-ui
- Back to registry: Browse all 10,085 compliance nodes