{"id":"T1685.003","name":"Modify or Spoof Tool UI","url":"https://attack.mitre.org/techniques/T1685/003","tactics":["defense-impairment"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0311","stix_id":"x-mitre-detection-strategy--fecfb9f9-645e-4e09-ba21-05bc60722688","name":"Detection for Spoofing Tool UI across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0311","analytics":[{"id":"AN0868","stix_id":"x-mitre-analytic--0f4ec296-008e-42aa-95b2-6e4e351d730c","name":"Analytic 0868","description":"Detection of inconsistencies between reported sensor health and actual process/service state. For example, Windows Defender tray icon/UI showing healthy status while corresponding Defender services (WinDefend, MsMpEng) are stopped or disabled. Correlates process creation events with missing or terminated security processes and spoofed health events.","url":"https://attack.mitre.org/detectionstrategies/DET0311#AN0868","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=7036","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ServiceNameList","description":"Monitored list of critical security service names; environment-specific."},{"field":"FakeUIProcessPatterns","description":"Patterns of filenames or paths mimicking Windows Security GUI elements."}],"live":true,"detection_strategies":["DET0311"],"techniques":["T1685.003"]},{"id":"AN0869","stix_id":"x-mitre-analytic--d1feb97f-3683-49f5-b5a8-b54d58de3444","name":"Analytic 0869","description":"Monitoring for discrepancies between system daemon/service state and reported health messages (e.g., syslog shows AV/IDS daemon stopped, but spoofed messages claim it is still running). Detects userland processes impersonating AV/IDS command-line outputs or modifying log forwarding configurations.","url":"https://attack.mitre.org/detectionstrategies/DET0311#AN0869","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of binaries/scripts presenting false health messages for security daemons","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Service stop or disable messages for security tools not reflected in SIEM alerts","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"SecurityDaemonList","description":"Names of AV/IDS/EDR daemons monitored in Linux environments."}],"live":true,"detection_strategies":["DET0311"],"techniques":["T1685.003"]},{"id":"AN0870","stix_id":"x-mitre-analytic--d9eb3056-115b-496a-89f7-be38470ff022","name":"Analytic 0870","description":"Detection of fake or spoofed macOS Security & Privacy GUIs showing healthy status after XProtect, Gatekeeper, or AV processes are disabled. Correlates user-space UI process creation with terminated or missing security daemons.","url":"https://attack.mitre.org/detectionstrategies/DET0311#AN0870","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of processes mimicking Apple Security & Privacy GUIs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Termination or disabling of XProtect, Gatekeeper, or third-party AV daemons","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TrustedDaemonList","description":"Monitored list of macOS security daemons such as XProtect, Gatekeeper, or third-party AV."}],"live":true,"detection_strategies":["DET0311"],"techniques":["T1685.003"]}],"live":true,"version":"1.0","techniques":["T1685.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}