Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.
Adversaries may disable or modify firewalls using different behaviors, depending on the platform. For example, in ESXi, firewall rules may be modified directly via the esxcli (e.g., via esxcli network firewall set) or via the vCenter user interface.
Rules on DetectionCode tagged with T1686 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Allow File And Printing Sharing In Firewall | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1686.001 |
| Allow Network Discovery In Firewall | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1686.001 |
| ASL AWS Network Access Control List Created with All Open Ports | TTP | NULL | ASL AWS CloudTrail | T1686.001 |
| ASL AWS Network Access Control List Deleted | Anomaly | NULL | ASL AWS CloudTrail | T1686.001 |
| AWS Network Access Control List Created with All Open Ports | TTP | NULL | AWS CloudTrail CreateNetworkAclEntry, AWS CloudTrail ReplaceNetworkAclEntry | T1686.001 |
| AWS Network Access Control List Deleted | Anomaly | NULL | AWS CloudTrail DeleteNetworkAclEntry | T1686.001 |
| ESXi Firewall Disabled | TTP | NULL | VMWare ESXi Syslog | T1686 |
| Firewall Allowed Program Enable | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1686 |
| Linux Auditd Disable Or Modify System Firewall | Anomaly | NULL | Linux Auditd Service Stop | T1686 |
| Linux Iptables Firewall Modification | Anomaly | NULL | Sysmon for Linux EventID 1 | T1686 |
| Linux Stdout Redirection To Dev Null File | Anomaly | NULL | Sysmon for Linux EventID 1 | T1686 |
| Microsoft Intune DeviceManagementConfigurationPolicies | Hunting | NULL | Azure Monitor Activity | T1686 |
| O365 Bypass MFA via Trusted IP | TTP | NULL | O365 Set Company Information. | T1686.001 |
| Processes launching netsh | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1686 |
| Windows Delete or Modify System Firewall | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1686 |
| Windows Firewall Rule Added | Anomaly | NULL | Windows Event Log Security 4946 | T1686 |
| Windows Firewall Rule Deletion | Anomaly | NULL | Windows Event Log Security 4948 | T1686 |
| Windows Firewall Rule Modification | Anomaly | NULL | Windows Event Log Security 4947 | T1686 |
| Windows Modify System Firewall with Notable Process Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1686 |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
| GroupCarbanak | Carbanak may use netsh to add local firewall rule exceptions. |
| GroupDragonfly | Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389. |
| GroupFIN7 | FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898. |
| GroupKimsuky | Kimsuky has been observed disabling the system firewall. |
| GroupMedusa Group | Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions. |
| GroupRocke | Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers. |
| Used by | Procedure example |
|---|---|
| MalwareBACKSPACE | The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed. |
| MalwareBPFDoor | BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port. |
| MalwareCookieMiner | CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found. |
| MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| MalwareHannotog | Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port. |
| MalwareHOPLIGHT | |
| MalwareInvisiMole | InvisiMole has a command to disable routing and the Firewall on the victim’s machine. |
| MalwareKasidet | Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded. |
| Used by | Procedure example |
|---|---|
| CampaignLeviathan Australian Intrusions | Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.