Watchdog Timer Status Disabled

Monitors for cases where the WDT status is set to disabled, which may signal tampering or exploitation by a threat actor. The status could also be suspended vice disabled. This could look like [x-opencti-watchdog:active = false] in STIX

STIX Pattern

[x-opencti-watchdog:status = 'disabled']

SPARTA TTPs

ID Name Description
DE-0003.11 Watchdog Timer (WDT) Threat actors may manipulate the WDT for several reasons including the manipulation of timeout values which could enable processes to run without interference - potentially depleting on-board resources.