Network Device Firewall

T1686.002

Sub-technique of T1686 Disable or Modify System Firewall.View on attack.mitre.org

About this technique

Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage.

Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic. For example, adversaries may add new network firewall rules to allow access to all internal network subnets without restrictions. Allowing access to internal network subsets may enable unrestricted inbound/outbound connectivity or open paths for command and control and lateral movement.

Adversaries may obtain access to network device management interfaces via Valid Accounts or by exploiting vulnerabilities. In some cases, threat actors may target firewalls and other network infrastructure that are exposed to the internet by leveraging weaknesses in public-facing applications (Exploit Public-Facing Application).

Adversaries may also modify host networking configurations that indirectly manipulate system firewalls, such as adjusting interface bandwidth or network connection request thresholds.

Detection rules2

Rules on DetectionCode tagged with T1686.002.

Sigma2

RuleLevelLog source
FortiGate - Firewall Address Object Addedmediumfortigate / NULL
FortiGate - New Firewall Policy Addedmediumfortigate / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software2

Campaigns1

Procedure examples4

Groups1

Used byProcedure example
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

Software2

Used byProcedure example
MalwareCyclops Blink

Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers.

MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

Campaigns1

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified security settings within the victims Fortigate device, utilizing the native CLI. During the 2025 Poland Wiper Attacks, the adversaries also disabled network traffic logging.

References1

  1. CVE-2024-55591 Detail Open source
    NIST NVD. (2025, January 22). Retrieved September 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.