ATT&CKMatrixDefense Impairment

Defense Impairment

TA0112

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.

Defense Impairment consists of techniques that degrade, disable, or undermine the effectiveness and trustworthiness of security controls and monitoring mechanisms. These techniques are characterized by direct interference with defensive systems. The goal is to reduce defenders’ ability to detect, interpret, or respond to adversary activity.

Techniques18

IDNameSub-techniquesExamples
T1112Modify Registry0173
T1207Rogue Domain Controller01
T1222File and Directory Permissions Modification228
T1484Domain or Tenant Policy Modification220
T1553Subvert Trust Controls6112
T1556Modify Authentication Process925
T1578Modify Cloud Compute Infrastructure56
T1599Network Boundary Bridging12
T1600Weaken Encryption20
T1601Modify System Image22
T1647Plist File Modification02
T1666Modify Cloud Resource Hierarchy00
T1685Disable or Modify Tools6188
T1686Disable or Modify System Firewall352
T1687Exploitation for Defense Impairment00
T1688Safe Mode Boot07
T1689Downgrade Attack03
T1690Prevent Command History Logging012

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.