Index / Techniques / Disable or Modify Tools
Technique Record · T1562.001

Disable or Modify Tools

Publicly-reported instances of Disable or Modify Tools bypassing endpoint security products. Maintained on the same basis for every technique in the Index.

51
recorded bypasses
22
products affected

Products recorded as bypassed by Disable or Modify Tools

ProductEntriesHigh-confidenceMost recent
Microsoft 17162026-05-21
Palo Alto Networks 662025-03-19
CrowdStrike 532025-09-29
SentinelOne 432025-11-17
Trend Micro 222024-07-14
multiple commercial EDR/AV vendors 102026-01-11
Riot Games 112025-06-26
Kaspersky 112023-09-13
Carbon Black 102023-06-01
Velociraptor 112025-08-28
Tanium 112025-08-28
Palo Alto 112023-09-13
Talsec 112024-12-05
Malwarebytes 112023-09-13
Avast Software 112025-11-11
Forcepoint 112026-03-26
Check Point 112023-09-13
VMware 112024-05-22
various AV/EDR vendors 102024-08-11
EasyAntiCheat 112024-07-02
Sysmon 112026-02-27
Symantec 112025-08-28

All entries

ProductConfidenceDisclosedSource
Microsoft high 2026-05-21Huntress record →
Forcepoint high 2026-03-26gist.github.com record →
Sysmon high 2026-02-27binarydefense.com record →
Microsoft high 2026-02-27binarydefense.com record →
multiple commercial EDR/AV vendors medium 2026-01-11cybernoz.com record →
Microsoft high 2026-01-11cybernoz.com record →
SentinelOne high 2025-11-17cyberpress.org record →
Microsoft high 2025-11-17cyberpress.org record →
Avast Software high 2025-11-11nvd.nist.gov record →
Microsoft high 2025-10-15windowsforum.com record →
Microsoft high 2025-09-29prevent-ransomware.com record →
CrowdStrike high 2025-09-29prevent-ransomware.com record →
Symantec high 2025-08-28beierle.win record →
Tanium high 2025-08-28beierle.win record →
Velociraptor high 2025-08-28beierle.win record →
SentinelOne high 2025-08-28beierle.win record →
CrowdStrike high 2025-08-28beierle.win record →
Microsoft high 2025-08-28beierle.win record →
Riot Games high 2025-06-26github.com record →
Microsoft high 2025-06-15github.com record →
Microsoft high 2025-06-10www.linkedin.com record →
Microsoft high 2025-04-08www.sentinelone.com record →
Palo Alto Networks high 2025-03-19security.paloaltonetworks.com record →
CrowdStrike high 2025-03-06securityaid.co.uk record →
Palo Alto Networks high 2025-02-12security.paloaltonetworks.com record →
Talsec high 2024-12-05regne.me record →
Microsoft high 2024-12-01cloudbrothers.info record →
Palo Alto Networks high 2024-10-15feedly.com record →
Microsoft high 2024-08-11dazzyddos.github.io record →
various AV/EDR vendors medium 2024-08-11dazzyddos.github.io record →
Palo Alto Networks high 2024-08-07feedly.com record →
Trend Micro high 2024-07-14www.satyamrastogi.com record →
EasyAntiCheat high 2024-07-02cheater.ninja record →
Palo Alto Networks high 2024-06-12blog.scrt.ch record →
Microsoft high 2024-05-29cybernoz.com record →
VMware high 2024-05-22ctid.mitre.org record →
Microsoft high 2024-04-24gbhackers.com record →
Microsoft high 2024-03-21blog.talosintelligence.com record →
Check Point high 2023-09-13labs.infoguard.ch record →
Microsoft high 2023-09-13labs.infoguard.ch record →
Palo Alto high 2023-09-13labs.infoguard.ch record →
Trend Micro high 2023-09-13labs.infoguard.ch record →
Malwarebytes high 2023-09-13labs.infoguard.ch record →
SentinelOne high 2023-09-13labs.infoguard.ch record →
CrowdStrike medium 2023-09-13labs.infoguard.ch record →
Kaspersky high 2023-09-13labs.infoguard.ch record →
Palo Alto Networks high 2023-07-07github.com record →
CrowdStrike medium 2023-06-01www.threatlocker.com record →
SentinelOne medium 2023-06-01www.threatlocker.com record →
Carbon Black medium 2023-06-01www.threatlocker.com record →
Microsoft medium 2023-06-01www.threatlocker.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file.