Compliance Node Overview
MITRE ATT&CK T1685 (Disable or Modify Tools) is an Enterprise Defense Impairment technique. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments. In addition to directly targeting tools, adversaries may block or manipulate indicators and telemetry used for detection. This includes maliciously disabling or redirecting sensors such as Event Tracing fo... Affected platforms: Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows. ATT&CK-mapped mitigations: M1018 User Account Management, M1047 Audit, M1022 Restrict File and Directory Permissions, M1042 Disable or Remove Feature or Program, M1054 Software Configuration, M1038 Execution Prevention, M1024 Restrict Registry Permissions.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1685/
SHA-256 integrity: 3683d3ebb6af2f48efd83d65c98cd8cf03a62612ee57b314e9502c77c6325370
Primary Citations — 11 traced to source
- MITRE ATT&CK Technique T1685: Disable or Modify Tools (https://attack.mitre.org/techniques/T1685/)
- MITRE ATT&CK Tactic TA0112: Defense Impairment (https://attack.mitre.org/tactics/TA0112/)
+ 9 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access