Skip to content
Threat Feed

Tag

Defense-Impairment

48 briefs RSS
medium advisory

Suspicious NTFS Symbolic Link Behavior Modification

Adversaries leverage the Windows fsutil utility to modify NTFS symbolic link evaluation settings, potentially facilitating privilege escalation or lateral movement via unconventional file path resolution.

defense-impairment execution windows ransomware
1r 2t
medium advisory

PowerShell GPO Configuration Modification

Adversaries may modify Group Policy settings via PowerShell to impair defensive capabilities or maintain persistence within a Windows environment.

defense-impairment privilege-escalation powershell
1r 2t
medium advisory

Suspicious Firewall Modification via WMI Provider Host

Detection of unauthorized Windows Firewall rule additions performed by the WMI Provider Host process, a technique associated with defense impairment by ransomware actors.

defense-impairment ransomware windows-security firewall
1r
high advisory

Detection of RDP Configuration Tampering via Reg.exe

Adversaries frequently target Windows Registry keys related to Terminal Services to enable remote access, bypass session restrictions, or weaken security layers during lateral movement and persistence.

persistence lateral-movement defense-impairment windows rdp
1r 2t
high advisory

Detection of Unauthorized Windows Defender Configuration Changes

Adversaries frequently disable or weaken Windows Defender security features to facilitate malware persistence and execution without detection.

defense-impairment windows security-telemetry
1r
high advisory

Tampering of RDP Terminal Services Registry Settings

Adversaries, including the DarkGate malware operators, modify sensitive registry keys associated with Terminal Services to facilitate session hijacking, unauthorized remote access, and defense impairment.

rdp registry persistence defense-impairment
1r 2t
high advisory

Tampering with Windows Defender via Registry Modifications

Adversaries frequently disable Windows Defender security features by modifying specific registry keys to impair endpoint detection and response capabilities.

defense-impairment windows-defender registry
1r
medium advisory

Windows Firewall Rule Deletion via Netsh.exe

Adversaries utilize the netsh.exe utility to impair host-based security by removing active firewall rules, potentially facilitating unauthorized lateral movement or command-and-control communication.

defense-impairment windows sysadmin-tooling
1r
medium advisory

Monitoring Restoration of Quarantined Files in Microsoft Defender

This brief documents the detection of file restoration events from the Microsoft Defender quarantine, a technique that can be leveraged by attackers to re-enable malicious payloads.

defense-impairment windows monitoring
1r
medium advisory

Monitoring Windows Defender Configuration Changes for Exclusion Additions

Detection of administrative or malicious modifications to Windows Defender settings that add file or path exclusions to the antimalware scanning engine.

defense-impairment configuration-monitoring windows
1r
medium advisory

Detection of MSIX Full Trust Package Installation

Detection of MSIX/AppX package installations requesting full trust capabilities which circumvent standard application container isolation and operate with elevated privileges.

execution persistence defense-impairment
1r 2t
high advisory

Modification of WDigest UseLogonCredential Registry Key

Adversaries modify the WDigest UseLogonCredential registry key to downgrade credential protection and enable the storage of clear-text passwords in memory for exfiltration via LSASS.

credential-theft persistence defense-impairment windows-registry
1r 2t
medium advisory

Suppression of Windows Security Center Notifications

Adversaries modify Windows Registry keys to disable Windows Security Center notifications, facilitating defense impairment and persistence.

persistence defense-impairment windows security-hardening
1r 2t
medium advisory

Windows Registry Explorer Policy Modifications

Adversaries, including the Agent Tesla malware, modify Windows Registry keys under Explorer Policies to impair user access to system tools and desktop functionality.

defense-impairment persistence windows registry
1r 1t
low advisory

Modification of Internet Explorer Registry Settings for Persistence

Detection of unauthorized modifications to Internet Explorer registry keys, which can be leveraged by attackers for persistence or defense impairment.

persistence defense-impairment
1r 2t
medium advisory

Potential Persistence via Event Viewer Registry Redirection

An adversary can achieve persistence or defense impairment by modifying Windows registry keys to redirect Event Viewer's 'Events.asp' link handling to a malicious binary or command line.

persistence defense-impairment windows registry
1r 1t
high advisory

Detection of Microsoft Office Protected View Disablement

Adversaries modify registry keys to disable Microsoft Office Protected View security controls, facilitating the execution of malicious documents.

Microsoft Office defense-impairment registry-tampering microsoft-office persistence privilege-escalation registry windows office
2r 1t updated
high advisory

Tampering with DisableRestrictedAdmin Registry Value

Attackers may modify the DisableRestrictedAdmin registry value to impair credential protection mechanisms by disabling Restricted Admin mode for Remote Desktop Services.

persistence defense-impairment windows
1r 2t
medium advisory

Registry Modifications Used to Obfuscate System UI Elements

Malicious actors, including those behind Agent Tesla and Hermetic Wiper, utilize specific registry modifications to hide system interface elements from users as a defensive impairment technique.

persistence defense-impairment windows registry
1r 1t
medium advisory

Modification of DisallowRun Registry Policy

An adversary or administrator can modify the DisallowRun registry key to prevent specific applications from executing, a technique often used to impair security tools or enforce restrictive environment configurations.

persistence defense-impairment registry windows
1r 1t
medium advisory

Defense Impairment via Windows Firewall Registry Modification

Adversaries disable the Windows Firewall by modifying specific registry keys to bypass network security controls and facilitate lateral movement or data exfiltration.

defense-impairment windows registry firewall
1r 1t
medium threat

Registry Modification to Disable Privacy Settings Experience

Adversaries, including those observed deploying LockBit Black, modify registry keys to disable the Windows Privacy Settings Experience as part of a defense impairment strategy.

LockBit Black defense-impairment registry-tampering
1r
high advisory

Detection of Suspicious Registry Key Modifications via Reg.exe

This brief documents detection logic for identifying potentially malicious registry modifications using the native Windows reg.exe utility to target sensitive system and persistence-related paths.

persistence defense-impairment windows reg
1r 2t
high advisory

PowerShell Defense Impairment via Set-MpPreference

Adversaries utilize PowerShell's Set-MpPreference cmdlet to disable Windows Defender security features and modify threat handling behavior, facilitating persistence and stealth.

defense-impairment windows powershell
1r 1t
high advisory

Abuse of PowerShell Disable-WindowsOptionalFeature for Defense Impairment

Adversaries leverage the Disable-WindowsOptionalFeature PowerShell cmdlet to disable security features like Windows Defender, facilitating defense impairment and persistence.

defense-impairment powershell windows-security
1r 1t
high advisory

Detection of PowerShell-Based DLL Placement in System Directories

Adversaries utilize PowerShell commands to move malicious DLLs into protected Windows system directories, a technique commonly associated with persistence and credential access.

persistence credential-access defense-impairment powershell
1r 1t
high advisory

Detection of Windows Defender Real-time Protection Impairment

This brief documents the detection logic for identifying when Windows Defender anti-malware scanning is disabled, a common TTP used by adversaries to impair system defenses.

defense-impairment windows security-telemetry
1r 1t
medium advisory

Windows Defender Real-time Protection Disabled

Detection of unauthorized disabling of Windows Defender real-time protection via system-level service events.

defense-impairment windows-defender
1r 1t
medium advisory

Detection of Windows Registry Modifications to Disable System Features

Adversaries, including operators of Agent Tesla and Batloader, modify Windows Registry keys to disable system administration tools and security features, hindering incident response and persistence.

Windows defense-impairment persistence registry
1r 2t
high advisory

Detection of Windows Service Binaries in Suspicious Directories

Adversaries often achieve persistence by registering malicious Windows services with binaries located in writeable or temp directories to evade detection.

persistence defense-impairment windows-registry detection-engineering
1r 1t
medium advisory

Detection of Unauthorized Windows Firewall Exception Rule Creation

Monitoring for non-standard additions to the Windows Defender Firewall exception list to identify potential defense impairment activity by unauthorized processes.

defense-impairment windows-firewall monitoring
1r
medium advisory

Detection of Suspicious Offline Registry Library Usage

Detection of unauthorized processes loading offreg.dll to perform direct registry hive modification, potentially bypassing standard Windows Registry auditing.

defense-impairment persistence windows telemetry-bypass
1r 1t
medium advisory

AWS Bedrock Guardrail Deleted

A detection rule has been developed for Amazon Bedrock that identifies the deletion of guardrails, indicating a potential attempt by an attacker or insider to disable AI model safety controls and facilitate unsafe or unauthorized responses.

AWS Bedrock aws cloud-security defense-impairment cloud ai llm defense-evasion
2r 2t
medium advisory

Detection of Sysmon Configuration Updates for Defense Evasion

This brief describes how to detect an attacker updating or replacing the Sysmon configuration with a bare bones one to avoid monitoring without completely shutting down the service, leveraging Sysmon's `-c` command-line option for defense impairment.

Sysmon windows defense-evasion defense-impairment
1r
high advisory

Potential Tampering With Security Products Via WMIC

Threat actors, including those behind IcedID, LockBit, and Vice Society, actively utilize the Windows Management Instrumentation Command-line (WMIC) utility to uninstall or terminate security products, aiming to impair host defenses and facilitate ransomware deployment or data exfiltration.

defense-impairment tampering wmic windows lolbin
1r 1t
medium advisory

FortiGate - New Firewall Policy Added

This brief describes a detection for the addition of new firewall policies on Fortinet FortiGate devices, a behavior that can indicate defense impairment or unauthorized network access by a malicious actor.

FortiGate defense-impairment firewall network
1r 1t
medium advisory

Potentially Suspicious WDAC Policy File Creation

Attackers may create Windows Defender Application Control (WDAC) policy files from abnormal processes to bypass Endpoint Detection and Response (EDR) or Antivirus (AV) solutions while allowing their own malicious code to execute on compromised Windows systems, impacting defense capabilities.

defense-impairment wdac application-control windows
1r 1t
medium advisory

Bitbucket Global SSH Settings Changed

An attacker modifies Bitbucket global SSH settings to potentially enable unauthorized access and lateral movement.

Bitbucket lateral-movement defense-impairment
2r 2t
low advisory

GitHub Push Protection Bypass Detection

Detection of a GitHub user bypassing push protection, potentially leading to the exposure of secrets.

Github defense-impairment t1685
2r
medium advisory

Azure Firewall Rule Collection Modification or Deletion

An attacker may modify or delete Azure Firewall rule collections (Application, NAT, and Network) to impair defenses and potentially enable malicious traffic.

Azure Firewall azure firewall defense-impairment
2r 2t
medium advisory

Spoofing AD FS Signing Logs via Azure AD Hybrid Health Service

A threat actor can create a new, rogue AD Health ADFS service within Azure and then create a fake server instance, which can be leveraged to spoof AD FS signing logs without compromising on-prem AD FS servers.

Azure Active Directory +1 cloud azure adfs defense-impairment
2r 1t
medium advisory

AWS CloudTrail Logging Disabled or Modified

Detection of AWS CloudTrail being disabled, deleted, or updated by an adversary to impair defenses and evade detection.

AWS CloudTrail defense-impairment cloud
3r 1t
medium advisory

Unauthorized Removal of Azure Conditional Access Policy

An unauthorized actor removes a Conditional Access policy in Azure, potentially weakening the organization's security posture and enabling privilege escalation or credential access.

Azure Active Directory azure conditional-access privilege-escalation credential-access persistence defense-impairment
2r 3t
low advisory

GitHub Repository Archive Status Changed

Detection of GitHub repository archiving or unarchiving events, which could indicate malicious activity such as persistence, impact, or defense impairment.

GitHub repository archive unarchive persistence impact defense-impairment
2r 3t
high advisory

AWS GuardDuty Detector Deletion or Disablement

Attackers may delete or disable AWS GuardDuty detectors to impair defenses and evade detection of malicious activities within the AWS environment.

GuardDuty defense-impairment aws cloudtrail
3r
medium advisory

Azure AD MFA Disabled to Bypass Authentication

An adversary may disable multi-factor authentication (MFA) in Azure Active Directory to weaken an organization's security posture and bypass authentication mechanisms, potentially gaining unauthorized access to sensitive resources and maintaining persistence.

Azure Active Directory azure mfa credential-access persistence defense-impairment
2r 1t
high advisory

Remote Registry Lateral Movement via RPC Firewall

This brief details detection of lateral movement attempts using remote RPC calls to modify the registry, potentially leading to code execution, detected via RPC Firewall logs.

lateral-movement defense-impairment persistence rpc
2r 3t
high advisory

AWS GuardDuty IP Set Manipulation for Defense Impairment

An attacker modifies AWS GuardDuty IP sets, potentially whitelisting malicious IPs to disable security alerts and impair defenses.

AWS GuardDuty defense-impairment aws
2r 1t