{"id":"T1689","name":"Downgrade Attack","url":"https://attack.mitre.org/techniques/T1689","tactics":["defense-impairment"],"platforms":["macOS","Windows","Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0350","stix_id":"x-mitre-detection-strategy--63d80d1b-ca5b-427d-b603-cf65e6e245b9","name":"Detecting Downgrade Attacks","url":"https://attack.mitre.org/detectionstrategies/DET0350","analytics":[{"id":"AN0995","stix_id":"x-mitre-analytic--e61d2099-1517-4bf4-b2e6-6e61cdf94be3","name":"Analytic 0995","description":"Detection of processes launching downgraded PowerShell versions (e.g., v2) or other legacy binaries that lack logging or security features. Correlates command-line arguments, process metadata, and version fields. Monitors registry changes to Defender or HVCI keys that could indicate intentional downgrades.","url":"https://attack.mitre.org/detectionstrategies/DET0350#AN0995","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"AllowedInterpreterVersions","description":"Defines which versions of interpreters like PowerShell are permitted in the environment."},{"field":"RegistryDefenderKeys","description":"Specific registry paths for monitoring Defender/HVCI configurations that may vary by Windows version."}],"live":true,"detection_strategies":["DET0350"],"techniques":["T1689"]},{"id":"AN0996","stix_id":"x-mitre-analytic--54eb86ed-2a72-41a8-b060-2750c2fee758","name":"Analytic 0996","description":"Monitors execution of older or legacy interpreters (e.g., python2, bash with restricted history logging), downgrade of TLS/SSL configurations, or forced fallback to unencrypted protocols. Detects suspicious reconfiguration of kernel modules or boot loaders to reduce integrity controls.","url":"https://attack.mitre.org/detectionstrategies/DET0350#AN0996","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of downgraded interpreters such as python2 or forced fallback commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Kernel or daemon warnings of downgraded TLS or cryptographic settings","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"AllowedCryptoProtocols","description":"List of TLS/SSL versions approved for use; alerts triggered if older protocols (e.g., TLS 1.0) are used."}],"live":true,"detection_strategies":["DET0350"],"techniques":["T1689"]},{"id":"AN0997","stix_id":"x-mitre-analytic--08a391a7-1ce6-4f11-b060-fca06ef03328","name":"Analytic 0997","description":"Detection of execution of legacy scripting runtimes (e.g., older versions of Python, Bash, or PowerShell Core) lacking auditing. Monitoring for changes to EFI or system boot files indicative of downgrade-based persistence or bypass of integrity features.","url":"https://attack.mitre.org/detectionstrategies/DET0350#AN0997","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of older or non-standard interpreters","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Modifications or writes to EFI system partition for downgraded bootloaders","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ApprovedInterpreterVersions","description":"Defines the minimal version of interpreters expected; older versions flagged as downgrade attempts."}],"live":true,"detection_strategies":["DET0350"],"techniques":["T1689"]}],"live":true,"version":"1.0","techniques":["T1689"]}],"sigma_rules":[{"id":"8c0eca51-0f88-4db2-9183-fdfb10c703f9","title":"LSA PPL Protection Setting Modification via CommandLine","author":"Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"medium","date":"2022-03-22","modified":"2026-03-13","description":"Detects modification of LSA PPL protection settings via CommandLine.\nIt may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.\n","references":["https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/","https://github.com/shoober420/windows11-scripts/blob/38d83331738cd713ccb42f2c4557d17a27aefd98/Windows11Tweaks.bat#L1825"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1689"],"path":"rules/windows/process_creation/proc_creation_win_lsa_ppl_protection_setting_modification_via_cli.yml","techniques":["T1689"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}