Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-578 — Disable Security Software
CAPEC-578

Disable Security Software

TLP:CLEAR

Description

Typical severity: Medium. Likelihood of attack: Medium. An adversary exploits a weakness in access control to disable security tools so that detection does not occur. This can take the form of killing processes, deleting registry keys so that tools do not start at run time, deleting log files, or other methods.

Mitigation

Ensure proper permissions are in place to prevent adversaries from altering the execution status of security tools.

Details

Platforms
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.