Tag
Suspicious NTFS Symbolic Link Behavior Modification
1 rule 2 TTPsAdversaries leverage the Windows fsutil utility to modify NTFS symbolic link evaluation settings, potentially facilitating privilege escalation or lateral movement via unconventional file path resolution.
PowerShell GPO Configuration Modification
1 rule 2 TTPsAdversaries may modify Group Policy settings via PowerShell to impair defensive capabilities or maintain persistence within a Windows environment.
Suspicious Firewall Modification via WMI Provider Host
1 ruleDetection of unauthorized Windows Firewall rule additions performed by the WMI Provider Host process, a technique associated with defense impairment by ransomware actors.
Detection of RDP Configuration Tampering via Reg.exe
1 rule 2 TTPsAdversaries frequently target Windows Registry keys related to Terminal Services to enable remote access, bypass session restrictions, or weaken security layers during lateral movement and persistence.
Detection of Unauthorized Windows Defender Configuration Changes
1 ruleAdversaries frequently disable or weaken Windows Defender security features to facilitate malware persistence and execution without detection.
Tampering of RDP Terminal Services Registry Settings
1 rule 2 TTPsAdversaries, including the DarkGate malware operators, modify sensitive registry keys associated with Terminal Services to facilitate session hijacking, unauthorized remote access, and defense impairment.
Tampering with Windows Defender via Registry Modifications
1 ruleAdversaries frequently disable Windows Defender security features by modifying specific registry keys to impair endpoint detection and response capabilities.
Windows Firewall Rule Deletion via Netsh.exe
1 ruleAdversaries utilize the netsh.exe utility to impair host-based security by removing active firewall rules, potentially facilitating unauthorized lateral movement or command-and-control communication.
Monitoring Restoration of Quarantined Files in Microsoft Defender
1 ruleThis brief documents the detection of file restoration events from the Microsoft Defender quarantine, a technique that can be leveraged by attackers to re-enable malicious payloads.
Monitoring Windows Defender Configuration Changes for Exclusion Additions
1 ruleDetection of administrative or malicious modifications to Windows Defender settings that add file or path exclusions to the antimalware scanning engine.
Detection of MSIX Full Trust Package Installation
1 rule 2 TTPsDetection of MSIX/AppX package installations requesting full trust capabilities which circumvent standard application container isolation and operate with elevated privileges.
Modification of WDigest UseLogonCredential Registry Key
1 rule 2 TTPsAdversaries modify the WDigest UseLogonCredential registry key to downgrade credential protection and enable the storage of clear-text passwords in memory for exfiltration via LSASS.
Suppression of Windows Security Center Notifications
1 rule 2 TTPsAdversaries modify Windows Registry keys to disable Windows Security Center notifications, facilitating defense impairment and persistence.
Windows Registry Explorer Policy Modifications
1 rule 1 TTPAdversaries, including the Agent Tesla malware, modify Windows Registry keys under Explorer Policies to impair user access to system tools and desktop functionality.
Modification of Internet Explorer Registry Settings for Persistence
1 rule 2 TTPsDetection of unauthorized modifications to Internet Explorer registry keys, which can be leveraged by attackers for persistence or defense impairment.
Potential Persistence via Event Viewer Registry Redirection
1 rule 1 TTPAn adversary can achieve persistence or defense impairment by modifying Windows registry keys to redirect Event Viewer's 'Events.asp' link handling to a malicious binary or command line.
Detection of Microsoft Office Protected View Disablement
2 rules 1 TTPAdversaries modify registry keys to disable Microsoft Office Protected View security controls, facilitating the execution of malicious documents.
Tampering with DisableRestrictedAdmin Registry Value
1 rule 2 TTPsAttackers may modify the DisableRestrictedAdmin registry value to impair credential protection mechanisms by disabling Restricted Admin mode for Remote Desktop Services.
Registry Modifications Used to Obfuscate System UI Elements
1 rule 1 TTPMalicious actors, including those behind Agent Tesla and Hermetic Wiper, utilize specific registry modifications to hide system interface elements from users as a defensive impairment technique.
Modification of DisallowRun Registry Policy
1 rule 1 TTPAn adversary or administrator can modify the DisallowRun registry key to prevent specific applications from executing, a technique often used to impair security tools or enforce restrictive environment configurations.
Defense Impairment via Windows Firewall Registry Modification
1 rule 1 TTPAdversaries disable the Windows Firewall by modifying specific registry keys to bypass network security controls and facilitate lateral movement or data exfiltration.
Registry Modification to Disable Privacy Settings Experience
1 ruleAdversaries, including those observed deploying LockBit Black, modify registry keys to disable the Windows Privacy Settings Experience as part of a defense impairment strategy.
Detection of Suspicious Registry Key Modifications via Reg.exe
1 rule 2 TTPsThis brief documents detection logic for identifying potentially malicious registry modifications using the native Windows reg.exe utility to target sensitive system and persistence-related paths.
PowerShell Defense Impairment via Set-MpPreference
1 rule 1 TTPAdversaries utilize PowerShell's Set-MpPreference cmdlet to disable Windows Defender security features and modify threat handling behavior, facilitating persistence and stealth.
Abuse of PowerShell Disable-WindowsOptionalFeature for Defense Impairment
1 rule 1 TTPAdversaries leverage the Disable-WindowsOptionalFeature PowerShell cmdlet to disable security features like Windows Defender, facilitating defense impairment and persistence.
Detection of PowerShell-Based DLL Placement in System Directories
1 rule 1 TTPAdversaries utilize PowerShell commands to move malicious DLLs into protected Windows system directories, a technique commonly associated with persistence and credential access.
Detection of Windows Defender Real-time Protection Impairment
1 rule 1 TTPThis brief documents the detection logic for identifying when Windows Defender anti-malware scanning is disabled, a common TTP used by adversaries to impair system defenses.
Windows Defender Real-time Protection Disabled
1 rule 1 TTPDetection of unauthorized disabling of Windows Defender real-time protection via system-level service events.
Detection of Windows Registry Modifications to Disable System Features
1 rule 2 TTPsAdversaries, including operators of Agent Tesla and Batloader, modify Windows Registry keys to disable system administration tools and security features, hindering incident response and persistence.
Detection of Windows Service Binaries in Suspicious Directories
1 rule 1 TTPAdversaries often achieve persistence by registering malicious Windows services with binaries located in writeable or temp directories to evade detection.
Detection of Unauthorized Windows Firewall Exception Rule Creation
1 ruleMonitoring for non-standard additions to the Windows Defender Firewall exception list to identify potential defense impairment activity by unauthorized processes.
Detection of Suspicious Offline Registry Library Usage
1 rule 1 TTPDetection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.
AWS Bedrock Guardrail Deleted
2 rules 2 TTPsA detection rule has been developed for Amazon Bedrock that identifies the deletion of guardrails, indicating a potential attempt by an attacker or insider to disable AI model safety controls and facilitate unsafe or unauthorized responses.
Detection of Sysmon Configuration Updates for Defense Evasion
1 ruleThis brief describes how to detect an attacker updating or replacing the Sysmon configuration with a bare bones one to avoid monitoring without completely shutting down the service, leveraging Sysmon's `-c` command-line option for defense impairment.
Potential Tampering With Security Products Via WMIC
1 rule 1 TTPThreat actors, including those behind IcedID, LockBit, and Vice Society, actively utilize the Windows Management Instrumentation Command-line (WMIC) utility to uninstall or terminate security products, aiming to impair host defenses and facilitate ransomware deployment or data exfiltration.
FortiGate - New Firewall Policy Added
1 rule 1 TTPThis brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.
Potentially Suspicious WDAC Policy File Creation
1 rule 1 TTPAttackers may create Windows Defender Application Control (WDAC) policy files from abnormal processes to bypass Endpoint Detection and Response (EDR) or Antivirus (AV) solutions while allowing their own malicious code to execute on compromised Windows systems, impacting defense capabilities.
Bitbucket Global SSH Settings Changed
2 rules 2 TTPsAn attacker modifies Bitbucket global SSH settings to potentially enable unauthorized access and lateral movement.
GitHub Push Protection Bypass Detection
2 rulesDetection of a GitHub user bypassing push protection, potentially leading to the exposure of secrets.
Azure Firewall Rule Collection Modification or Deletion
2 rules 2 TTPsAn attacker may modify or delete Azure Firewall rule collections (Application, NAT, and Network) to impair defenses and potentially enable malicious traffic.
Spoofing AD FS Signing Logs via Azure AD Hybrid Health Service
2 rules 1 TTPA threat actor can create a new, rogue AD Health ADFS service within Azure and then create a fake server instance, which can be leveraged to spoof AD FS signing logs without compromising on-prem AD FS servers.
AWS CloudTrail Logging Disabled or Modified
3 rules 1 TTPDetection of AWS CloudTrail being disabled, deleted, or updated by an adversary to impair defenses and evade detection.
Unauthorized Removal of Azure Conditional Access Policy
2 rules 3 TTPsAn unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.
GitHub Repository Archive Status Changed
2 rules 3 TTPsDetection of GitHub repository archiving or unarchiving events, which could indicate malicious activity such as persistence, impact, or defense impairment.
AWS GuardDuty Detector Deletion or Disablement
3 rulesAttackers may delete or disable AWS GuardDuty detectors to impair defenses and evade detection of malicious activities within the AWS environment.
Azure AD MFA Disabled to Bypass Authentication
2 rules 1 TTPAn adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.
Remote Registry Lateral Movement via RPC Firewall
2 rules 3 TTPsThis brief details detection of lateral movement attempts using remote RPC calls to modify the registry, potentially leading to code execution, detected via RPC Firewall logs.
AWS GuardDuty IP Set Manipulation for Defense Impairment
2 rules 1 TTPAn attacker modifies AWS GuardDuty IP sets, potentially whitelisting malicious IPs to disable security alerts and impair defenses.