// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE PUB-ENTDTG 0600Z
ColdReconTechniquesT1562
Technique T1562

Impair Defenses

CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
Impair Defenses (T1562) — a Defense Evasion technique, observed in public incident reporting.
MITRE ATT&CKT1562
TacticDefense Evasion
Incidents on file25

Detection & mitigation

Monitor for loading of known vulnerable or abused Microsoft-signed drivers (e.g., via Sysmon Event ID 6 or driver load events) and correlate with process termination of security products. Enforce driver block rules using Windows Defender Application Control or vulnerable driver blocklist to prevent loading of abused drivers.

Observed in the wild

Track this in real time.

ColdRecon watches the public signal so you don't have to — a daily brief and a live detection-coverage desk. Request clearance.

Request Clearance →