| Azure AD Block User Consent For Risky Apps Disabled | TTP | NULL | Azure Active Directory Update authorization policy | T1685 |
| Cisco ASA - Core Syslog Message Volume Drop | Hunting | NULL | Cisco ASA Logs | T1685 |
| Cisco ASA - Logging Disabled via CLI | TTP | NULL | Cisco ASA Logs | T1685 |
| Cisco ASA - Logging Filters Configuration Tampering | Anomaly | NULL | Cisco ASA Logs | T1685 |
| Cisco ASA - Logging Message Suppression | Anomaly | NULL | Cisco ASA Logs | T1685.001 |
| Cisco Configuration Archive Logging Analysis | Hunting | NULL | Cisco IOS Logs | T1685 |
| Cisco SNMP Community String Configuration Changes | Anomaly | NULL | Cisco IOS Logs | T1685 |
| Disable AMSI Through Registry | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Defender AntiVirus Registry | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Defender BlockAtFirstSeen Feature | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Defender Enhanced Notification | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Defender MpEngine Registry | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Defender Spynet Reporting | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Defender Submit Samples Consent Feature | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable ETW Through Registry | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Logs Using WevtUtil | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.005 |
| Disable Registry Tool | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Schedule Task | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Disable Show Hidden Files | Anomaly | NULL | Sysmon EventID 13 | T1685 |
| Disable Windows App Hotkeys | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Windows Behavior Monitoring | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disable Windows SmartScreen Protection | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disabling CMD Application | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disabling ControlPanel | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disabling Defender Services | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disabling Firewall with Netsh | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Disabling FolderOptions Windows Feature | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disabling NoRun Windows App | TTP | NULL | Sysmon EventID 13 | T1685 |
| Disabling Task Manager | TTP | NULL | Sysmon EventID 13 | T1685 |
| ESXi Download Errors | Anomaly | NULL | VMWare ESXi Syslog | T1685 |
| ESXi Encryption Settings Modified | TTP | NULL | VMWare ESXi Syslog | T1685 |
| ESXi Lockdown Mode Disabled | TTP | NULL | VMWare ESXi Syslog | T1685 |
| ESXi Loghost Config Tampering | TTP | NULL | VMWare ESXi Syslog | T1685 |
| ESXi VIB Acceptance Level Tampering | TTP | NULL | VMWare ESXi Syslog | T1685 |
| ETW Registry Disabled | TTP | NULL | Sysmon EventID 13 | T1685 |
| Excessive number of service control start as disabled | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Excessive Usage Of Taskkill | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| GitHub Enterprise Delete Branch Ruleset | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685 |
| GitHub Enterprise Disable 2FA Requirement | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685 |
| GitHub Enterprise Disable Audit Log Event Stream | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685.002 |
| GitHub Enterprise Disable Classic Branch Protection Rule | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685 |
| GitHub Enterprise Disable Dependabot | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685 |
| GitHub Enterprise Disable IP Allow List | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685 |
| GitHub Enterprise Modify Audit Log Event Stream | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685.002 |
| GitHub Enterprise Pause Audit Log Event Stream | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685.002 |
| GitHub Enterprise Register Self Hosted Runner | Anomaly | NULL | GitHub Enterprise Audit Logs | T1685 |
| GitHub Organizations Delete Branch Ruleset | Anomaly | NULL | GitHub Organizations Audit Logs | T1685 |
| GitHub Organizations Disable 2FA Requirement | Anomaly | NULL | GitHub Organizations Audit Logs | T1685 |
| GitHub Organizations Disable Classic Branch Protection Rule | Anomaly | NULL | GitHub Organizations Audit Logs | T1685 |
| GitHub Organizations Disable Dependabot | Anomaly | NULL | GitHub Organizations Audit Logs | T1685 |
| Hide User Account From Sign-In Screen | TTP | NULL | Sysmon EventID 13 | T1685 |
| Linux Auditd Auditd Daemon Abort | Anomaly | NULL | Linux Auditd Daemon Abort | T1685.004 |
| Linux Auditd Auditd Daemon Shutdown | Anomaly | NULL | Linux Auditd Daemon End | T1685.004 |
| Linux Auditd Auditd Daemon Start | Anomaly | NULL | Linux Auditd Daemon Start | T1685.004 |
| Linux Impair Defenses Process Kill | Hunting | NULL | Sysmon for Linux EventID 1 | T1685 |
| M365 Copilot Agentic Jailbreak Attack | Anomaly | NULL | M365 Exported eDiscovery Prompts | T1685 |
| M365 Copilot Impersonation Jailbreak Attack | TTP | NULL | M365 Exported eDiscovery Prompts | T1685 |
| M365 Copilot Information Extraction Jailbreak Attack | TTP | NULL | M365 Exported eDiscovery Prompts | T1685 |
| M365 Copilot Jailbreak Attempts | Anomaly | NULL | M365 Exported eDiscovery Prompts | T1685 |
| M365 Copilot Non Compliant Devices Accessing M365 Copilot | Anomaly | NULL | M365 Copilot Graph API | T1685 |
| Microsoft Intune DeviceManagementConfigurationPolicies | Hunting | NULL | Azure Monitor Activity | T1685 |
| O365 Advanced Audit Disabled | TTP | NULL | O365 Change user license. | T1685.002 |
| O365 Block User Consent For Risky Apps Disabled | TTP | NULL | O365 Update authorization policy. | T1685 |
| O365 Email Security Feature Changed | TTP | NULL | Office 365 Universal Audit Log | T1685.002 |
| Powershell Disable Security Monitoring | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Powershell Remove Windows Defender Directory | Anomaly | NULL | Powershell Script Block Logging 4104 | T1685 |
| Powershell Windows Defender Exclusion Commands | Anomaly | NULL | Powershell Script Block Logging 4104 | T1685 |
| Process Kill Base On File Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Suspicious wevtutil Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.005 |
| Unload Sysmon Filter Driver | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Unloading AMSI via Reflection | TTP | NULL | Powershell Script Block Logging 4104 | T1685 |
| Windows AD Domain Controller Audit Policy Disabled | TTP | NULL | Windows Event Log Security 4719 | T1685 |
| Windows AD GPO Deleted | TTP | NULL | Windows Event Log Security 5136 | T1685 |
| Windows AD GPO Disabled | TTP | NULL | Windows Event Log Security 5136 | T1685 |
| Windows Attempt To Stop Security Service | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Audit Policy Auditing Option Disabled via Auditpol | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Audit Policy Cleared via Auditpol | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Audit Policy Disabled via Auditpol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Audit Policy Disabled via Legacy Auditpol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Audit Policy Excluded Category via Auditpol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Audit Policy Restored via Auditpol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Audit Policy Security Descriptor Tampering via Auditpol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Cisco Secure Endpoint Unblock File Via Sfc | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows CrowdStrike Agent Registry Key Removal | Anomaly | NULL | Sysmon EventID 12 | T1685 |
| Windows Defender ASR or Threat Configuration Tamper | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Defender Exclusion Registry Entry | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Disable or Modify Tools Via Taskkill | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Disable or Stop Browser Process | TTP | NULL | Sysmon EventID 1 | T1685 |
| Windows Disable Windows Event Logging Disable HTTP Logging | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows DisableAntiSpyware Registry | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows DISM Remove Defender | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows EDRSilencer Custom Outbound Filter Added | TTP | NULL | Windows Event Log Security 5441, Windows Event Log Security 5447 | T1685 |
| Windows EDRSilencer Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Event For Service Disabled | Hunting | NULL | Windows Event Log System 7040 | T1685 |
| Windows Event Log Cleared | TTP | NULL | Windows Event Log Security 1102, Windows Event Log System 104 | T1685.005 |
| Windows Event Logging Service Has Shutdown | Hunting | NULL | Windows Event Log Security 1100 | T1685.005 |
| Windows Eventlog Cleared Via Wevtutil | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.005 |
| Windows Excessive Disabled Services Event | TTP | NULL | Windows Event Log System 7040 | T1685 |
| Windows Filtering Platform Filter Added To Block EDR Process | TTP | NULL | Windows Event Log Security 5447 | T1685 |
| Windows Filtering Platform Policy Added to Block EDR Process | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Global Object Access Audit List Cleared Via Auditpol | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685.001 |
| Windows Impair Defense Add Xml Applocker Rules | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Impair Defense Change Win Defender Health Check Intervals | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Change Win Defender Quick Scan Interval | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Change Win Defender Throttle Rate | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Change Win Defender Tracing Level | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Configure App Install Control | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Define Win Defender Threat Action | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Delete Win Defender Context Menu | Hunting | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Delete Win Defender Profile Registry | Anomaly | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Deny Security Software With Applocker | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Controlled Folder Access | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Defender Firewall And Network | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Defender Protocol Recognition | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable PUA Protection | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Realtime Signature Delivery | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Web Evaluation | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender App Guard | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender Compute File Hashes | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender Gen reports | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender Network Protection | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender Report Infection | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender Scan On Update | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Disable Win Defender Signature Retirement | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Overide Win Defender Phishing Filter | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Override SmartScreen Prompt | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defense Set Win Defender Smart Screen Level To Warn | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defenses Disable Auto Logger Session | Anomaly | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defenses Disable HVCI | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Impair Defenses Disable Win Defender Auto Logging | Anomaly | NULL | Sysmon EventID 13 | T1685 |
| Windows Important Audit Policy Disabled | TTP | NULL | Windows Event Log Security 4719 | T1685 |
| Windows Increase in Group or Object Modification Activity | TTP | NULL | Windows Event Log Security 4663 | T1685 |
| Windows Increase in User Modification Activity | TTP | NULL | Windows Event Log Security 4720 | T1685 |
| Windows MpCmdRun RemoveDefinitions Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows New Custom Security Descriptor Set On EventLog Channel | Anomaly | NULL | Sysmon EventID 13 | T1685.001 |
| Windows New EventLog ChannelAccess Registry Value Set | Anomaly | NULL | Sysmon EventID 13 | T1685.001 |
| Windows Outlook Dialogs Disabled from Unusual Process | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows PowerShell Disable HTTP Logging | TTP | NULL | Powershell Script Block Logging 4104 | T1685.001 |
| Windows Powershell Import Applocker Policy | Anomaly | NULL | Powershell Script Block Logging 4104 | T1685 |
| Windows Raccine Scheduled Task Deletion | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |
| Windows Registry Delete Task SD | Anomaly | NULL | Sysmon EventID 12 | T1685 |
| Windows Registry Dotnet ETW Disabled Via ENV Variable | TTP | NULL | Sysmon EventID 13 | T1685 |
| Windows Terminating Lsass Process | Anomaly | NULL | Sysmon EventID 10 | T1685 |
| Wmic NonInteractive App Uninstallation | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1685 |