M ManySignal
TA0005 ATT&CK Tactic

Defense Evasion

Adversaries invest heavily in remaining undetected. Defense evasion techniques disable security tools, remove evidence, and obfuscate malicious activity. ManySignal's immutable log ingestion and behavioural analytics detect these techniques even when attackers try to cover their tracks.

Coverage

Techniques covered
42
Detection rules
74
Log-tamper rules
14

Threat context

How adversaries evade detection

Defense evasion is where sophisticated adversaries differentiate themselves. Commodity attackers trigger obvious alerts; nation-state actors and experienced ransomware operators disable logging, clear event logs, and operate under legitimate credentials before deploying their primary payload. The goal is to extend dwell time — the longer they operate undetected, the more damage they can inflict or data they can exfiltrate.

ManySignal counters evasion through immutable log ingestion (events are stored in ManySignal before attackers can delete local copies), behavioural anomaly detection (operating under a valid account still leaves behavioural traces), and connector health monitoring (a silenced data source is itself an alert).

Defense Evasion: frequently asked questions

What is ATT&CK Defense Evasion (TA0005)?

Defense Evasion covers techniques adversaries use to avoid detection and analysis by security tools. It is the most diverse ATT&CK tactic with over 40 techniques, reflecting how much adversaries invest in staying hidden.

How does ManySignal detect log tampering if the logs are cleared?

ManySignal ingests logs as they are generated and ships them to its own storage immediately. Clearing local Windows Event Logs or disabling CloudTrail removes the local copy but not what ManySignal has already ingested. The clearing event itself generates a high-priority alert.

Can attackers disable ManySignal itself?

ManySignal's connectors run as separate processes with minimal footprint. Disabling them requires platform-level access. ManySignal monitors connector health and alerts when event delivery stops unexpectedly — a connector going silent is itself a defense evasion indicator.

Detect evasion before attackers disappear into the noise

ManySignal's immutable log ingestion and behavioural analytics catch defense evasion techniques even when attackers disable local logging.