Bypass Record
Disable or Modify Tools × Microsoft Windows 11
A publicly-reported instance of Disable or Modify Tools bypassing Microsoft Windows 11, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
The attack abuses the Windows Update process to downgrade critical system components (e.g., kernel, drivers, security features) to older versions with known vulnerabilities. It bypasses integrity checks by manipulating update metadata and using legitimate update mechanisms, effectively turning a fully patched system into a vulnerable one. This defeats VBS, HVCI, and can disable security software by downgrading their components or re-enabling vulnerable drivers.
Detection & mitigation
Monitor for unexpected downgrades of security components via Windows Update logs and event IDs (e.g., Event ID 19 for Windows Update). Deploy endpoint detection that alerts on changes to VBS/HVCI configuration or attempts to load older, vulnerable drivers. Enforce strict control over update policies and use application control to block known vulnerable binaries.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.