Indicator Blocking
An adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed. This could include maliciously redirecting(Citation: Microsoft Lamin Sept 2017) or even disabling host-based sensors, such as Event Tracing for Windows (ETW)(Citation: Microsoft About Event Tracing 2018), by tampering settings that control the collection and flow of event telemetry.(Citation: Medium Event Tracing Tampering 2018) These settings may be stored on the system in conf...
BY SOURCE
PROCEDURES (10)
Auto-extracted: 3 detections for cloud monitoring
Auto-extracted: 2 detections for persist
Auto-extracted: 2 detections for process creation monitoring
Auto-extracted: 2 detections for general monitoring
Auto-extracted: 2 detections for powershell
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for powershell
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for amsi
Auto-extracted: 1 detections for amsi