Detection Playbook: Disable Windows Event Logging (T1562.002)

T1562.002 · 2026-07-17 Disable Windows Event Logging Defense Evasion MITRE ATT&CK → Technique Disable Windows Event Logging (T1562.002) Tactic Defense Evasion Platforms Windows, Linux, macOS Overview Disable Windows Event Logging (T1562.002) covers attacker actions that stop, corrupt, or suppress the Windows event logging pipeline — most commonly by tampering with the Windows Event Log service, … Read more

Detection Playbook: Disable or Modify Security Tools (T1562.001)

T1562.001 · 2026-07-16 Disable or Modify Security Tools Defense Evasion MITRE ATT&CK → Technique Disable or Modify Security Tools (T1562.001) Tactic Defense Evasion Platforms Windows, Linux, macOS Overview Disable or Modify Security Tools (T1562.001) describes attacker actions taken to impair, stop, or tamper with defensive software — including antivirus engines, EDR agents, host-based firewalls, logging … Read more

Detection Playbook: Clear Windows Event Logs (T1070.001)

T1070.001 · 2026-07-15 Clear Windows Event Logs Defense Evasion MITRE ATT&CK → Technique Clear Windows Event Logs (T1070.001) Tactic Defense Evasion Platforms Windows, Linux, macOS Overview Clear Windows Event Logs (T1070.001) is a defense evasion technique where attackers delete or wipe Windows event log channels — such as Security, System, Application, or custom logs — … Read more

Detection Playbook: Process Injection (T1055)

T1055 · 2026-07-14 Process Injection Stealth Linux macOS Windows MITRE ATT&CK → Technique Process Injection (T1055) Tactic Stealth Platforms Linux, macOS, Windows Overview Process injection (T1055) is a technique where adversaries insert and execute arbitrary code within the address space of a running, legitimate process. By hijacking a trusted process, attackers can access its memory, … Read more

Detection Playbook: Token Impersonation/Theft (T1134.001)

T1134.001 · 2026-07-13 Token Impersonation/Theft Stealth Windows MITRE ATT&CK → Technique Token Impersonation/Theft (T1134.001) Tactic Stealth Platforms Windows Overview Token Impersonation/Theft (T1134.001) is a Windows privilege escalation technique in which an adversary duplicates an existing access token belonging to another user or process — typically one running with elevated privileges — and then impersonates that … Read more

Detection Playbook: DNS (T1071.004)

T1071.004 · 2026-07-12 DNS Command And Control ESXi Linux macOS Network Devices MITRE ATT&CK → Technique DNS (T1071.004) Tactic Command And Control Platforms ESXi, Linux, macOS, Network Devices, Windows Overview DNS tunneling (T1071.004) is a command-and-control technique where adversaries embed data — including commands and exfiltrated output — inside DNS query and response packets. Because … Read more

Detection Playbook: Web Protocols (T1071.001)

T1071.001 · 2026-07-11 Web Protocols Command And Control ESXi Linux macOS Network Devices MITRE ATT&CK → Technique Web Protocols (T1071.001) Tactic Command And Control Platforms ESXi, Linux, macOS, Network Devices, Windows Overview Web Protocols (T1071.001) describes adversaries using HTTP, HTTPS, and WebSocket as the transport layer for command-and-control (C2) communication. Rather than inventing custom protocols, … Read more

Detection Playbook: Service Stop (T1489)

T1489 · 2026-07-10 Service Stop Impact ESXi IaaS Linux macOS MITRE ATT&CK → Technique Service Stop (T1489) Tactic Impact Platforms ESXi, IaaS, Linux, macOS, Windows Overview Service Stop (T1489) is a technique where adversaries deliberately halt or disable running services on a target system to prevent legitimate users from accessing them or to enable follow-on … Read more

Detection Playbook: Inhibit System Recovery (T1490)

T1490 · 2026-07-09 Inhibit System Recovery Impact Containers ESXi IaaS Linux MITRE ATT&CK → Technique Inhibit System Recovery (T1490) Tactic Impact Platforms Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows Overview Inhibit System Recovery (T1490) describes adversary actions taken to delete, disable, or corrupt the built-in recovery mechanisms of an operating system or platform — … Read more

Detection Playbook: Data Encrypted for Impact (T1486)

T1486 · 2026-07-08 Data Encrypted for Impact Impact ESXi IaaS Linux macOS MITRE ATT&CK → Technique Data Encrypted for Impact (T1486) Tactic Impact Platforms ESXi, IaaS, Linux, macOS, Windows Overview Data Encrypted for Impact (T1486) describes adversary activity where files, drives, or entire systems are encrypted to deny the victim access to their own data. … Read more