T1562 Impair Defenses — Detection & Response
Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as firewalls and anti-virus, but also detection capabilities that defenders use to audit activity and identify malicious behavior.
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 3+
Threat context
How adversaries use T1562 Impair Defenses — Detection & Response
Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as firewalls and anti-virus, but also detection capabilities that defenders use to audit activity and identify malicious behavior.
Log tampering (T1562.002 and T1562.008) is a reliable indicator of a sophisticated, long-dwell intrusion. In cloud environments, attackers with sufficient permissions disable CloudTrail, delete CloudTrail trails, or modify S3 bucket policies to prevent log delivery. Endpoint AV/EDR tampering is common ransomware pre-deployment activity — the attacker disables or uninstalls security tools before deploying the encryptor. ManySignal's own telemetry absence is a defense-impairment signal: a connector that stops delivering events is alerting evidence.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| CloudTrail StopLogging — AWS CloudTrail trail logging disabled A principal calls StopLogging on a CloudTrail trail, disabling audit logging for the account or region. | Critical | AWS CloudTrail |
| CloudTrail Trail Deleted — Entire CloudTrail trail deleted DeleteTrail API call removes an active CloudTrail trail, destroying future audit log coverage. | Critical | AWS CloudTrail |
| EDR Agent Tamper Detected — CrowdStrike or SentinelOne sensor disabled on host Endpoint security agent reports tamper detection or goes offline without a corresponding planned maintenance event. | Critical | CrowdStrike / SentinelOne |
| Windows Audit Policy Disabled — Security audit subcategory set to No Auditing Audit policy change (Event ID 4719) disables a security audit category, reducing detection coverage. | High | Windows Event Log |
| GuardDuty Detector Disabled — AWS GuardDuty detector deactivated DisableOrganizationAdminAccount or DeleteDetector call disables GuardDuty coverage for an account. | Critical | AWS CloudTrail |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1562 Impair Defenses — Detection & Response: frequently asked questions
What happens if an attacker deletes the CloudTrail trail before ManySignal detects it?
The DeleteTrail event itself is recorded in CloudTrail before the trail is deleted. ManySignal receives and alerts on this event. For the period after deletion (while the attacker operates), there will be a gap in CloudTrail coverage, which is itself a forensic indicator.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.