Skip to content

Hide Navigation Hide TOC

Agent Disabling of Host Security Controls - ATR-2026-01993 (77f71a88-3a3b-583a-ab81-bff2e54dcf3f)

Detects an agent tool call that disables or tears down a host defense: stopping/flushing the firewall, disabling SELinux/AppArmor, turning off or clearing the audit daemon, stopping an EDR/AV service, or wiping shell history to hide activity. This is the agent-context form of ATT&CK T1562 (Impair Defenses) — the agent is being driven to blind the host before or during an intrusion. Detects: explicit disable/stop/flush/clear commands against named security controls. Does NOT detect: application/build teardown (docker compose down, rm node_modules), or reading the status of a control.

Cluster A Galaxy A Cluster B Galaxy B Level
Agent Disabling of Host Security Controls - ATR-2026-01993 (77f71a88-3a3b-583a-ab81-bff2e54dcf3f) Agent Threat Rules Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 1
Agent Disabling of Host Security Controls - ATR-2026-01993 (77f71a88-3a3b-583a-ab81-bff2e54dcf3f) Agent Threat Rules User Execution (8c849dd4-5d15-45aa-b5b2-59c96a3ab939) MITRE ATLAS Attack Pattern 1
Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 2