open-menu
closeme
Add SafeBoot Keys Via Reg Utility
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AMSI Bypass Pattern Assembly GetType
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.execution
·
Share on:
twitter
facebook
linkedin
copy
AMSI Disabled via Registry Modification
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Antivirus Filter Driver Disallowed On Dev Drive - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ASLR Disabled Via Sysctl or Direct Syscall - Linux
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1685
attack.t1055.009
·
Share on:
twitter
facebook
linkedin
copy
Auditing Configuration Changes on Linux Host
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Detector Deleted Or Updated
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.t1685.002
·
Share on:
twitter
facebook
linkedin
copy
AWS GuardDuty Important Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
AWS SecurityHub Findings Evasion
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Azure Kubernetes Events Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Audit Log Configuration Updated
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global Secret Scanning Rule Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Global SSH Settings Changed
calendar
Apr 28, 2026
·
attack.lateral-movement
attack.defense-impairment
attack.t1685
attack.t1021.004
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Project Secret Scanning Allowlist Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Exempt Repository Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Bitbucket Secret Scanning Rule Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Cisco Disabling Logging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Cisco Dot1x Disabled
calendar
Apr 28, 2026
·
attack.persistence
attack.credential-access
attack.defense-impairment
attack.t1685
attack.t1556.004
·
Share on:
twitter
facebook
linkedin
copy
Devcon Execution Disabling VMware VMCI Device
calendar
Apr 28, 2026
·
attack.persistence
attack.privilege-escalation
attack.defense-impairment
attack.t1543.003
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Diamond Sleet APT Scheduled Task Creation - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Disable Exploit Guard Network Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable of ETW Trace - Powershell
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Disable Or Stop Services
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.impact
attack.t1489
·
Share on:
twitter
facebook
linkedin
copy
Disable Privacy Settings Experience in Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable PUA Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Security Tools
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Tamper Protection on Windows Defender
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Defender AV Security Monitoring
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable Windows Defender Functionalities Via Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disable-WindowsOptionalFeature Command PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled IE Security Features
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled Volume Snapshots
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabled Windows Defender Eventlog
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Disabling Windows Defender WMI Autologger Session via Reg.exe
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Dism Remove Online Package
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ESXi Syslog Configuration Change Via ESXCLI
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
attack.t1690
attack.t1059.012
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For rpcrt4.dll
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled For SCM
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Disabled In .NET Processes - Sysmon Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Logging Tamper In .NET Processes Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
ETW Trace Evasion Activity
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
car.2016-04-002
·
Share on:
twitter
facebook
linkedin
copy
Filter Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Folder Removed From Exploit Guard ProtectedFolders List - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - Firewall Address Object Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
FortiGate - New Firewall Policy Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Bypass Detected
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Github Push Protection Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Github Secret Scanning Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Google Cloud Firewall Modified or Deleted
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - CobaltStrike BOF Injection Pattern
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1106
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hacktool - EDR-Freeze Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EDRSilencer Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - EDRSilencer Execution - Filter Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - PowerTool Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
HackTool - Stracciatella Execution
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hide Schedule Task Via Index Value Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor Enforced Paging Translation Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Kaspersky Endpoint Security Stopped Via CommandLine - Linux
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By A Suspicious Process
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1486
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Load Of RstrtMgr.DLL By An Uncommon Process
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1486
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Logging Configuration Changes on Linux Host
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Defender Tamper Protection Trigger
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Malware Protection Engine Crash - WER
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1211
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Microsoft Office Protected View Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
NetNTLM Downgrade Attack - Registry
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1685
attack.t1112
·
Share on:
twitter
facebook
linkedin
copy
Obfuscated PowerShell OneLiner Execution
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1059.001
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Okta User Session Start Via An Anonymising Proxy Service
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Script Using NULL Bits
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Using NULL Bits
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI Bypass Via .NET Reflection
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential AMSI COM Server Hijacking
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Ke3chang/TidePool Malware Activity
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.g0004
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Potential Privileged System Service Operation - SeLoadDriverPrivilege
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Suspicious Activity Using SeCEdit
calendar
Apr 28, 2026
·
attack.collection
attack.discovery
attack.persistence
attack.credential-access
attack.privilege-escalation
attack.execution
attack.stealth
attack.defense-impairment
attack.t1685.001
attack.t1547.001
attack.t1505.005
attack.t1556.002
attack.t1685
attack.t1574.007
attack.t1564.002
attack.t1546.008
attack.t1546.007
attack.t1547.014
attack.t1547.010
attack.t1547.002
attack.t1557
attack.t1082
·
Share on:
twitter
facebook
linkedin
copy
Potential Tampering With Security Products Via WMIC
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Potential Windows Defender Tampering Via Wmic.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1047
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Base64 Encoded MpPreference Cmdlet
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Defender Disable Scan Feature
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Powershell Defender Exclusion
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
PPL Tampering Via WerFaultSecure
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.credential-access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
PUA - CleanWipe Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Python Function Execution Security Warning Disabled In Excel
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Python Function Execution Security Warning Disabled In Excel - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Raccine Uninstall
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
RedSun - Named Pipe Created
calendar
Apr 28, 2026
·
attack.privilege-escalation
attack.stealth
attack.defense-impairment
attack.t1055
attack.t1685
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
RedSun - TieringEngineService.exe Detected as EICAR Test File
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1036.005
attack.t1685
attack.privilege-escalation
attack.t1055
detection.emerging-threats
·
Share on:
twitter
facebook
linkedin
copy
Reg Add Suspicious Paths
calendar
Apr 28, 2026
·
attack.persistence
attack.defense-impairment
attack.t1112
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal Of AMSI Provider Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal Of Index Value to Hide Schedule Task - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Removal Of SD Value to Hide Schedule Task - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
SafeBoot Registry Key Deleted Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Scripted Diagnostics Turn Off Check Enabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Security Service Disabled Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service Registry Key Deleted Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service Startup Type Change Via Wmic.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1047
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service StartupType Change Via PowerShell Set-Service
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Service StartupType Change Via Sc.EXE
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Application Allowed Through Exploit Guard
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1003
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Path In Keyboard Layout IME File Registry Value
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
calendar
Apr 28, 2026
·
attack.credential-access
attack.defense-impairment
attack.t1003.001
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious PROCEXP152.sys File Created In TMP
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Service Installed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Uninstall of Windows Defender Feature via PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Service Tampering
calendar
Apr 28, 2026
·
attack.impact
attack.defense-impairment
attack.t1489
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.t1685.005
·
Share on:
twitter
facebook
linkedin
copy
Sysinternals PsSuspend Suspicious Execution
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Application Crashed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Configuration Update
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Altitude Change
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Sysmon Driver Unloaded Via Fltmc.EXE
calendar
Apr 28, 2026
·
attack.stealth
attack.defense-impairment
attack.t1070
attack.t1685
attack.t1685.001
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender - PSClassic
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender Remove-MpPreference
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Tamper With Sophos AV Registry Keys
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Taskkill Symantec Endpoint Protection
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uncommon Extension In Keyboard Layout IME File Registry Value
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Crowdstrike Falcon Sensor
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Uninstall Sysinternals Sysmon
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Vulnerable Driver Blocklist Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Weak Encryption Enabled and Kerberoast
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
WFP Filter Added via Registry
calendar
Apr 28, 2026
·
attack.execution
attack.defense-impairment
attack.t1685
attack.t1569.002
·
Share on:
twitter
facebook
linkedin
copy
Win Defender Restored Quarantine File
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows AMSI Related Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Disabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Registry Tampering Via CommandLine
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Credential Guard Related Registry Value Deleted - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Configuration Changes
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Context Menu Removed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Definition Files Removed
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion List Modified
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusion Registry Key - Write Access Requested
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added - PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
attack.execution
attack.t1059
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exclusions Added - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Exploit Guard Tamper
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Grace Period Expired
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Malware And PUA Scanning Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-time Protection Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Real-Time Protection Failure/Restart
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Service Disabled - Registry
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Submit Sample Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Detection Service Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Threat Severity Default Action Modified
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Defender Virus Scanning Feature Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Filtering Platform Blocked Connection From EDR Agent Binary
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Firewall Disabled via PowerShell
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Hypervisor Enforced Code Integrity Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Windows Vulnerable Driver Blocklist Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
Write Protect For Storage Disabled
calendar
Apr 28, 2026
·
attack.defense-impairment
attack.t1685
·
Share on:
twitter
facebook
linkedin
copy
to-top