kevmap

TechniquesT1685 › AN1369

AN1369 Analytic 1369

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry.</p>
Detects
T1685 Disable or Modify Tools
Part of
DET0497 Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SystemEventCode=7045DC0060 Service Creation
WinEventLog:SysmonEventCode=5DC0033 Process Termination
WinEventLog:SysmonEventCode=13, 14DC0063 Windows Registry Key Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ProcessNameExclusionsList of expected administrative tools/processes to prevent false positives.
TimeWindowDefines correlation window linking process termination, registry edits, and service stoppage.
ServiceNamesCustomizable list of security service names per enterprise deployment.