Downgrade Attack

T1689

Technique.View on attack.mitre.org

About this technique

Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of a system’s backward compatibility to force it into less secure modes of operation.

Adversaries may downgrade and use various less-secure versions of features of a system, such as Command and Scripting Interpreter or even network protocols that can be abused to enable Adversary-in-the-Middle or Network Sniffing. For example, PowerShell versions 5+ includes Script Block Logging (SBL), which can record executed script content. However, adversaries may attempt to execute a previous version of PowerShell that does not support SBL with the intent to impair defenses while running malicious scripts that may have otherwise been detected.

Adversaries may similarly target network traffic to downgrade from an encrypted HTTPS connection to an unsecured HTTP connection that exposes network data in clear text. On Windows systems, adversaries may downgrade the boot manager to a vulnerable version that bypasses Secure Boot, granting the ability to disable various operating system security mechanisms.

Detection rules3

Rules on DetectionCode tagged with T1689.

Sigma1

RuleLevelLog source
LSA PPL Protection Setting Modification via CommandLinemediumwindows / process_creation

Splunk2

RuleTypeRiskData source
PowerShell 4104 HuntingHuntingNULLPowershell Script Block Logging 4104
Windows Downdate Registry ActivityAnomalyNULLSysmon EventID 12, Sysmon EventID 13, Sysmon EventID 14

Groups0

None recorded.

Software2

Campaigns1

Procedure examples3

Software2

Used byProcedure example
MalwareBlackByte Ransomware

BlackByte Ransomware enables SMBv1 during execution.

ToolSILENTTRINITY

SILENTTRINITY can downgrade NTLM to capture NTLM hashes.

Campaigns1

Used byProcedure example
CampaignFrostyGoop Incident

During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment.

References7

  1. CrowdStrike Downgrade attack 2 Open source
    Bart Lenaerts-Bergmans. (2023, March 13). What are Downgrade Attacks?. Retrieved April 15, 2026.
  2. CrowdStrike downgrade attack Open source
    Falcon Complete Team. (2021, May 11). Response When Minutes Matter: Rising Up Against Ransomware. Retrieved April 15, 2026.
  3. Google Cloud downgrade attack Open source
    Nathan Kirk. (2018, June 18). Bring Your Own Land (BYOL) — A Novel Red Teaming Technique. Retrieved April 15, 2026.
  4. Praetorian TLS Downgrade Attack 2014 Open source
    Praetorian. (2014, August 19). Man-in-the-Middle TLS Protocol Downgrade Attack. Retrieved October 8, 2021.
  5. SafeBreach Open source
    Alon Leviev. (2024, August 7). Windows Downdate: Downgrade Attacks Using Windows Updates. Retrieved January 8, 2025.
  6. Targeted SSL Stripping Attacks Are Real Open source
    Check Point. (n.d.). Targeted SSL Stripping Attacks Are Real. Retrieved May 24, 2023.
  7. att_def_ps_logging Open source
    Hao, M. (2019, February 27). Attack and Defense Around PowerShell Event Logging. Retrieved November 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.