Agent Disabling of Host Security Controls - ATR-2026-01993 (77f71a88-3a3b-583a-ab81-bff2e54dcf3f)
Detects an agent tool call that disables or tears down a host defense: stopping/flushing the firewall, disabling SELinux/AppArmor, turning off or clearing the audit daemon, stopping an EDR/AV service, or wiping shell history to hide activity. This is the agent-context form of ATT&CK T1562 (Impair Defenses) — the agent is being driven to blind the host before or during an intrusion. Detects: explicit disable/stop/flush/clear commands against named security controls. Does NOT detect: application/build teardown (docker compose down, rm node_modules), or reading the status of a control.