An experienced attacker may seek to disable or bypass defense mechanisms.
For example, he might try to:
- disable an antivirus
- stop a service
- modify a configuration
- delete logs
- modify firewall rules
- disable monitoring mechanisms.
These actions are particularly interesting to monitor. MITRE ATT&CK notably documents detection strategies targeting behaviors related to the alteration of defense mechanisms.