M ManySignal
T1562 MITRE ATT&CK

T1562 Impair Defenses — Detection & Response

Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as firewalls and anti-virus, but also detection capabilities that defenders use to audit activity and identify malicious behavior.

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
3+

Threat context

How adversaries use T1562 Impair Defenses — Detection & Response

Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing preventative defenses, such as firewalls and anti-virus, but also detection capabilities that defenders use to audit activity and identify malicious behavior.

Log tampering (T1562.002 and T1562.008) is a reliable indicator of a sophisticated, long-dwell intrusion. In cloud environments, attackers with sufficient permissions disable CloudTrail, delete CloudTrail trails, or modify S3 bucket policies to prevent log delivery. Endpoint AV/EDR tampering is common ransomware pre-deployment activity — the attacker disables or uninstalls security tools before deploying the encryptor. ManySignal's own telemetry absence is a defense-impairment signal: a connector that stops delivering events is alerting evidence.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

CloudTrail StopLogging — AWS CloudTrail trail logging disabled

A principal calls StopLogging on a CloudTrail trail, disabling audit logging for the account or region.

Critical AWS CloudTrail

CloudTrail Trail Deleted — Entire CloudTrail trail deleted

DeleteTrail API call removes an active CloudTrail trail, destroying future audit log coverage.

Critical AWS CloudTrail

EDR Agent Tamper Detected — CrowdStrike or SentinelOne sensor disabled on host

Endpoint security agent reports tamper detection or goes offline without a corresponding planned maintenance event.

Critical CrowdStrike / SentinelOne

Windows Audit Policy Disabled — Security audit subcategory set to No Auditing

Audit policy change (Event ID 4719) disables a security audit category, reducing detection coverage.

High Windows Event Log

GuardDuty Detector Disabled — AWS GuardDuty detector deactivated

DisableOrganizationAdminAccount or DeleteDetector call disables GuardDuty coverage for an account.

Critical AWS CloudTrail

T1562 Impair Defenses — Detection & Response: frequently asked questions

What happens if an attacker deletes the CloudTrail trail before ManySignal detects it?

The DeleteTrail event itself is recorded in CloudTrail before the trail is deleted. ManySignal receives and alerts on this event. For the period after deletion (while the attacker operates), there will be a gap in CloudTrail coverage, which is itself a forensic indicator.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.