Under Defense Evasion one of the evasion techniques is "Misconfiguration of security measures". I believe this should be more like "disable security measures" or perhaps "disable or misconfigure security measures".
In my experience, it's much more common for attackers to totally disable a control like a GitHub Action, or endpoint detection than it is for them to do the more challenging thing which is to misconfigure it.