TechKnowSurge
VideoSecurityFree

Disabled Defenses

Attackers routinely disable security tools like firewalls, antivirus, and EDR systems to avoid detection after gaining access to a network. Recognizing disabled defenses is a critical indicator of potential compromise.

Complete this video to capture a CTF flag worth 1 point.

About this video

Adversaries who gain access to a network frequently attempt to disable security defenses as a way to avoid detection and extend their presence undetected. Security tools commonly targeted include firewalls, antivirus software, endpoint detection and response platforms, intrusion detection and prevention systems, and SIEMs. When one or more of these controls go offline without a clear, authorized reason, it should be treated as a potential indicator of compromise rather than a routine configuration issue. A well-secured network can still be undermined if an attacker has sufficient access to tamper with its defensive layers. For example, a Windows host showing a disabled firewall on a private network segment may appear to be a minor misconfiguration, but it could equally reflect deliberate action by a threat actor who wants to operate without triggering alerts. Security teams need to actively monitor the status of all deployed defenses and investigate any unexpected changes, treating disabled tools as a red flag that warrants immediate attention and investigation.

What you'll learn

What's covered

Disabled Defenses Detection

Key terms

Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Antivirus
Software designed to detect, prevent, and remove malicious software from a system.
Endpoint Detection and Response
EDR
A security solution that continuously monitors endpoint devices to detect, investigate, and respond to threats.
Intrusion Detection System
IDS
A system that monitors network or system activities for malicious behavior and generates alerts.
Intrusion Prevention System
IPS
A system that monitors network traffic and actively blocks detected threats in real time.
Security Information and Event Management
SIEM
A system that aggregates and analyzes security event data from across an organization to detect and respond to threats.
Defense Evasion
A MITRE ATT&CK tactic in which adversaries take actions to avoid being detected by security tools and personnel during an attack.

Topics

Defense Evasion Endpoint Detection And Response Antivirus Firewall Threat Detection Cybersecurity Incident Response

Transcript

One thing an adversary is going to do is disable any kind of defenses so that way they don't get caught on your network.

Here we have a network. It has a firewall on it. It has an intrusion detection system and an intrusion prevention system, a SIEM, a firewall, antivirus, an EDR system. HIDS and HIPS are all set up on the computer. So we've got this network really well protected.

However, for some reason, some of these services have gone offline. Maybe this host doesn't have a firewall turned on, the antivirus is turned off, the EDR is disabled. So what is happening here? Is it a new user that's turning that off, or is there an attacker on the system and they don't want to be caught, so they've turned these systems off? So we need to watch out for disabled defenses. If there's disabled defenses, that could be a sign that there's some sort of attack or compromise.

I'm on a Windows server here and we can see the firewall and network protection settings, and it's giving us a red X. That's because it's turned off. It's on what it's considering a private network, and the firewall is off on this network. And so this is just one thing that we may want to look into and say, well, why is this off? Is this the setting that it's supposed to be on this network, or is this supposed to be turned on?

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →