T1686 Disable or Modify System Firewall
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- All Rules Have Been Deleted From The Windows Firewall Configurationhightest · windows
- Disable System Firewallhightest · linux
- New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Applicationhightest · windows
- RDP Connection Allowed Via Netsh.EXEhightest · windows
- Suspicious Program Location Whitelisted In Firewall Via Netsh.EXEhightest · windows
- A Rule Has Been Deleted From The Windows Firewall Exception Listmediumtest · windows
- Azure Firewall Modified or Deletedmediumtest · azure
- Azure Firewall Rule Collection Modified or Deletedmediumtest · azure
- Azure Network Firewall Policy Modified or Deletedmediumtest · azure
- Bpfdoor TCP Ports Redirectmediumtest · linux
- Disable Microsoft Defender Firewall via Registrymediumtest · windows
- Disable Windows Firewall by Registrymediumtest · windows
- Disabling Security Toolsmediumtest · linux
- Disabling Security Tools - Builtinmediumtest · linux
- Firewall Disabled via Netsh.EXEmediumtest · windows
- Firewall Rule Deleted Via Netsh.EXEmediumtest · windows
- Flush Iptables Ufw Chainmediumtest · linux
- Modify System Firewallmediumtest · linux
- Netsh Allow Group Policy on Microsoft Defender Firewallmediumtest · windows
- New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXEmediumtest · windows
- New Firewall Rule Added Via Netsh.EXEmediumtest · windows
- New Network Route Addedmediumtest · aws
- UFW Disable Attemptmediumtest · linux
- Uncommon New Firewall Rule Added In Windows Firewall Exception Listmediumtest · windows
- Windows Firewall Profile Disabledmediumtest · windows
Showing 25 of 27.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.