Azure Add Verified Domain
Adds a custom domain to a Microsoft Entra ID tenant and initiates the domain verification process.
The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.
Defense Impairment consists of techniques that degrade, disable, or undermine the effectiveness and trustworthiness of security controls and monitoring mechanisms. These techniques are characterized by direct interference with defensive systems. The goal is to reduce defenders’ ability to detect, interpret, or respond to adversary activity.
In cloud environments, adversaries impair defenses by disabling or deleting logging services (CloudTrail, Azure diagnostic settings, GCP logging sinks), modifying or removing security group and firewall rules, tampering with audit logs, or stopping monitoring services like GuardDuty and Microsoft Defender for Cloud.
Defense Impairment (TA0112) was introduced in ATT&CK v19 (April 2026), when the former Defense Evasion tactic was split into Stealth and Defense Impairment.
View Defense Impairment on MITRE ATT&CK →Adds a custom domain to a Microsoft Entra ID tenant and initiates the domain verification process.
Archives GuardDuty findings to suppress active security alerts from SOC visibility.
Adds inbound rules to an RDS DB security group, allowing specified IP ranges or EC2 security groups to access the database.
Adds outbound rules to a VPC security group, permitting traffic from instances to specified destination IP ranges or security groups.
Adds inbound rules to a VPC security group, permitting traffic from specified IP ranges or security groups to reach instances.
Deletes a firewall rule from a GCP VPC network.
Modifies an existing firewall rule in a GCP VPC network.
Creates a GuardDuty finding filter that automatically suppresses or highlights findings matching specified criteria.
Creates a GuardDuty IP set — a trusted-IP allowlist whose addresses GuardDuty excludes from findings.
Adds an allow or deny rule to a Network ACL, controlling traffic entering or leaving a specific VPC subnet.
Deactivates an MFA device associated with an IAM user, removing the MFA requirement for their authentication.
Deletes one or more CloudWatch alarms, removing their monitoring configurations and associated notifications.
Permanently deletes an S3 bucket; the bucket must be empty before deletion can succeed.
Deletes an AWS Config rule that was evaluating the compliance of AWS resource configurations.
Deletes the AWS Config configuration recorder, stopping resource configuration recording in the region.
Deletes the AWS Config delivery channel, stopping delivery of configuration snapshots and change notifications to S3 or SNS.
Disables and permanently deletes a GuardDuty detector in the region, stopping all threat detection.
Deletes a CloudTrail Lake event data store, destroying stored forensic evidence and audit logs.
Deletes VPC Flow Log configurations, stopping the capture of network traffic metadata for the specified resources.
Permanently deletes a CloudWatch Logs log group and all its log streams and stored data.
Removes an IAM user's console password, preventing them from signing in to the AWS Management Console.
Permanently deletes a log stream and all its events from within a CloudWatch Logs log group.
Removes member accounts from a GuardDuty administrator account, ending the delegated monitoring relationship.
Deletes a Network ACL from a VPC; the default NACL cannot be deleted.
Removes a rule from a Network ACL, modifying traffic filtering for the associated VPC subnet.
Deletes multiple S3 objects in a single batch request, more efficient than individual delete operations.
Deletes an inline policy embedded directly in an IAM role.
Permanently deletes a WAF rule group containing a set of web traffic filtering rules.
Permanently deletes a CloudTrail trail, stopping API activity logging for that trail configuration.
Deletes an inline policy embedded directly in an IAM user.
Deletes a virtual MFA device, weakening account security by removing multi-factor authentication.
Permanently deletes a WAF Web ACL used to protect web applications from common web threats.
Detaches a managed IAM policy from a role, removing those permissions from the role's effective policy.
Detaches a managed IAM policy from an IAM user, removing those permissions from the user.
Disassociates the current account from its GuardDuty administrator account, ending the delegated monitoring relationship.
Disassociates specified member accounts from a GuardDuty administrator account.
Mutes Security Command Center findings, suppressing security alerts from visibility.
Modifies a logging exclusion filter to silently drop specific log entries, hiding ongoing attacker activity.
Deletes log entries from Cloud Logging, destroying forensic evidence of attacker activity.
Removes the current member account from its AWS Organization; the management account cannot leave.
Creates a log exclusion rule in Cloud Logging that prevents matching log entries from being ingested.
Deletes a Cloud Logging sink that was routing log entries to a destination such as Cloud Storage or BigQuery.
Modifies a Cloud Logging sink's configuration, such as its destination or log filter criteria.
Permanently deletes an Azure virtual machine.
Permanently deletes an Azure Event Hub entity within a namespace.
Removes an extension from an Azure Arc-enabled server.
Deletes an activity log alert rule, disabling security detection and notification capabilities.
Deletes an Azure Monitor diagnostic setting, stopping the forwarding of logs and metrics to a configured destination.
Deletes an Azure Monitor metric alert rule.
Deletes a network security group, removing network access controls from associated resources.
Creates or updates a security rule in an Azure Network Security Group, controlling inbound or outbound traffic.
Deletes an NSG flow log configuration, stopping the capture of network traffic metadata for a network security group.
Creates or modifies a virtual network peering, enabling network connectivity for lateral movement across VNets.
Permanently deletes a Log Analytics workspace and its stored data.
Creates or updates a suppression rule in Microsoft Defender for Cloud, hiding matching security alerts.
Modifies auto-provisioning settings, potentially disabling automatic deployment of security monitoring agents.
Changes the pricing tier (plan) for Microsoft Defender for Cloud on a subscription or specific resource type.
Removes a security solution integrated with Microsoft Defender for Cloud.
Stops logging for an Azure Storage account, disabling the collection of storage analytics logs.
Modifies a specific attribute of an EC2 instance, such as its instance type, user data, or security groups.
Sets lifecycle rules on an S3 bucket to automatically transition objects to cheaper storage tiers or expire them.
Configures which API events (management or data, read/write) a CloudTrail trail records.
Removes an AWS account from the organization, stripping it of SCP protections and centralized security controls.
Schedules a KMS customer managed key for deletion after a waiting period (7-30 days), after which encrypted data is unrecoverable.
Updates the settings or configuration of Google Security Command Center for the organization or project.
Stops AWS Config from recording resource configuration changes in the region.
Stops logging API activity for a CloudTrail trail, disabling audit log collection for that trail.
Stops GuardDuty from monitoring specified member accounts under an administrator account.
Modifies an existing Conditional Access policy, changing the conditions or controls that govern how users authenticate.
Updates a named location definition (IP ranges or countries) used in Entra ID Conditional Access policy conditions.
Changes the MFA or passwordless authentication methods registered for a user in Microsoft Entra ID.
Updates the configuration of a GuardDuty detector, such as enabling or disabling specific threat detection data sources.
Modifies the IP addresses or CIDR ranges in a GuardDuty trusted-IP set (allowlist), whose entries GuardDuty excludes from findings.
Modifies the configuration of an existing CloudTrail trail, such as its S3 bucket, log validation, or multi-region settings.
Updates the properties of an Azure Key Vault, such as its access policies, network rules, or soft-delete configuration.