Attackers routinely disable security tools like firewalls, antivirus, and EDR systems to avoid detection after gaining access to a network. Recognizing disabled defenses is a critical indicator of potential compromise.
Disabled Defenses Detection
One thing an adversary is going to do is disable any kind of defenses so that way they don't get caught on your network.
Here we have a network. It has a firewall on it. It has an intrusion detection system and an intrusion prevention system, a SIEM, a firewall, antivirus, an EDR system. HIDS and HIPS are all set up on the computer. So we've got this network really well protected.
However, for some reason, some of these services have gone offline. Maybe this host doesn't have a firewall turned on, the antivirus is turned off, the EDR is disabled. So what is happening here? Is it a new user that's turning that off, or is there an attacker on the system and they don't want to be caught, so they've turned these systems off? So we need to watch out for disabled defenses. If there's disabled defenses, that could be a sign that there's some sort of attack or compromise.
I'm on a Windows server here and we can see the firewall and network protection settings, and it's giving us a red X. That's because it's turned off. It's on what it's considering a private network, and the firewall is off on this network. And so this is just one thing that we may want to look into and say, well, why is this off? Is this the setting that it's supposed to be on this network, or is this supposed to be turned on?
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →