This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Modify System Firewall
Original Source:
[Sigma source]
Title:
Modify System Firewall
Status:
test
Description:
Detects the removal of system firewall rules. Adversaries may only delete or modify a specific system firewall rule to bypass controls limiting network usage or access. Detection rules that match only on the disabling of firewalls will miss this.
References:
-https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html
-https://blog.aquasec.com/container-security-tnt-container-attack
-https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/getting-started-with-nftables_configuring-and-managing-networking
Author:
IAI
Date:
2023-03-06
modified:
2025-10-12
Tags:
-'attack.defense-impairment'
-'attack.t1686'
Logsource:
product: linux
service: auditd
Detection:
selection1:
type
:
'EXECVE'
a0
:
'iptables'
a1|contains
:
'DROP'
selection2:
type
:
'EXECVE'
a0
:
'firewall-cmd'
a1|contains
:
'remove'
selection3:
type
:
'EXECVE'
a0
:
'ufw'
a1|contains
:
'delete'
selection4:
type
:
'EXECVE'
a0
:
'nft'
a1|contains
:
-'delete'
-'flush'
condition
:
1 of selection*
Falsepositives:
-Legitimate admin activity
Level:
medium