Basyrix SOC Response Atlas by Basyrix

Defense Impairment

T1685 — Disable or Modify Tools

Adversaries may disable, degrade, or tamper with security tools -- EDR, antivirus, logging agents, sensors -- to impair or reduce visibility of defensive capabilities. This also includes blocking or manipulating the indicators and telemetry those tools rely on for detection, not just disabling the tool itself. Formerly tracked as "Impair Defenses" (T1562), renamed and moved to the Defense Impairment tactic.

Any tampering with security controls (EDR uninstall/exclusion, log clearing, firewall or Conditional Access policy change) should be treated as a high-confidence indicator of active, deliberate intrusion rather than routine administration, because legitimate reasons to disable these controls are rare and should already be tracked as changes.

Platforms

Windows, Linux, macOS, Azure AD, Office 365

Priority / status

high / complete

Evidence to collect

  • Host or tenant affected
  • Control disabled/modified
  • Initiating process, user, or service principal
  • Timestamp of change
  • Prior and current configuration state