T1686.002 Network Device Firewall
Sub-technique of T1686 Disable or Modify System Firewall
Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage. Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic. For example,…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- FortiGate - Firewall Address Object Addedmediumexperimental · fortigate
- FortiGate - New Firewall Policy Addedmediumexperimental · fortigate
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.