Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0900 — Detection of Defense Impairment
DET0900

Detection of Defense Impairment

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN2038 Analytic 2038
Windows

Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution.

WinEventLog:System EventCode=7035 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=6 WinEventLog:Security EventCode=4688
[CrashCorrelationWindow] Time between suspicious interaction and security service failure
[ProtectedServiceList] Security agents/services expected to remain stable
[TelemetryGapThreshold] Acceptable heartbeat silence duration
AN2039 Analytic 2039
Linux

Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation.

auditd:EXECVE execve, kill, ptrace, insmod, rmmod targeting security processes auditd:DAEMON auditd stopped, config changed, logging suspended
[ProtectedProcessNames] Names of EDR, audit, AV, firewall daemons
[ModuleUnloadAllowlist] Approved maintenance unload operations
[HealthGapThreshold] Expected telemetry heartbeat tolerance
AN2040 Analytic 2040
macOS

Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption.

macos:unifiedlog Crash or abnormal termination of security agent or system extension host macos:unifiedlog Extension disabled, unloaded, failed to start NSM:Flow Traffic spike preceding control crash
[ExtensionList] Protected security system extensions
[CrashBurstThreshold] Multiple failures in short interval
AN2041 Analytic 2041
IaaS

Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage.

AWS:CloudTrail StopLogging, DeleteTrail, or DisableSecurityService AWS:CloudTrail ModifyInstanceAttribute AWS:CloudTrail AuthorizeSecurityGroupIngress
[CriticalTrailList] Audit trails that must remain enabled
[ControlChangeWindow] Time after suspicious API sequence to inspect coverage loss
AN2042 Analytic 2042
SaaS

Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction.

saas:okta policy.rule.update;system.log.disable;admin.role.assign m365:unified Set-AdminAuditLogConfig;New-ApplicationAccessPolicy;ConsentToApplication
[PrivilegedActorAllowlist] Approved admins allowed to change controls
[RetentionChangeThreshold] Minimum acceptable logging retention

Detected Techniques

1

Details

MITRE ID
DET0900
STIX ID
x-mitre-detection-strategy--3a3820cd-260b-43d0-b5af-89b7ba81a044
Analytics
5
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.