Techniques › T1562
T1562 Impair Defenses revoked
stealth — Windows, IaaS, Linux, macOS, Containers, Network Devices, Identity Provider, Office Suite, ESXi · attack.mitre.org · JSON
Revoked in ATT&CK; superseded by T1685. Shown because CTID mappings still reference it.
0
MITRE detection strategies
0
analytics
0
Sigma rules tagged attack.t1562
3
KEV CVEs mapped here
<p>Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as firewalls and anti-virus, but also detection capabilities that defenders can use to audit activity and identify malicious behavior. This may also span both native defenses as well as supplemental capabilities installed by users and administrators.</p><p>Adversaries may also impair routine operations that contribute to defensive hygiene, such as blocking users from logging out, preventing a system from shutting down, or disabling or modifying the update process. Adversaries could also target event aggregation and analysis mechanisms, or otherwise disrupt these procedures by altering other system components. These restrictions can further enable malicious operations as well as the continued propagation of incidents.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2023-0386 | Linux Kernel | secondary impact | Stale | 2025-06-17 |
| CVE-2025-31201 | Apple Multiple Products | secondary impact | Stale | 2025-04-17 |
| CVE-2025-31200 | Apple Multiple Products | secondary impact | Stale | 2025-04-17 |
Detection strategy · ATT&CK Enterprise v19.2
MITRE publishes no detection strategy for this technique in v19.2.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1562
No Sigma rule carries this tag. 3 actively exploited CVEs map here.