{"id":"T1686","name":"Disable or Modify System Firewall","url":"https://attack.mitre.org/techniques/T1686","tactics":["defense-impairment"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0145","stix_id":"x-mitre-detection-strategy--acb9a314-aa08-4a0f-b3ba-201d87fa4cc8","name":"Detection of Disabled or Modified System Firewalls across OS Platforms.","url":"https://attack.mitre.org/detectionstrategies/DET0145","analytics":[{"id":"AN0406","stix_id":"x-mitre-analytic--df0f8f0a-1e92-415d-b15e-63cea928973a","name":"Analytic 0406","description":"Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy also indicate adversarial actions.","url":"https://attack.mitre.org/detectionstrategies/DET0145#AN0406","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredCommands","description":"List of admin tools and scripts allowed to legitimately modify firewall settings."},{"field":"AlertThreshold","description":"Number of firewall rule changes within a time window before triggering alert."}],"live":true,"detection_strategies":["DET0145"],"techniques":["T1686"]},{"id":"AN0407","stix_id":"x-mitre-analytic--3327048a-e90c-47e5-9b67-d2ecaa89523c","name":"Analytic 0407","description":"Detection of iptables, nftables, or firewalld rule modifications. Correlation of sudden drops in active firewall rules with suspicious processes suggests adversarial evasion.","url":"https://attack.mitre.org/detectionstrategies/DET0145#AN0407","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: iptables, nft, firewall-cmd modifications","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"execution of known firewall binaries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"AllowedScripts","description":"Baseline admin scripts allowed to make firewall modifications."}],"live":true,"detection_strategies":["DET0145"],"techniques":["T1686"]},{"id":"AN0408","stix_id":"x-mitre-analytic--38c74fcf-2a4d-45cd-8465-b5d80a605bd8","name":"Analytic 0408","description":"Detection of PF firewall rule modifications via pfctl, socketfilterfw, or defaults write to com.apple.alf. Adversaries often disable firewall profiles entirely or whitelist malicious processes.","url":"https://attack.mitre.org/detectionstrategies/DET0145#AN0408","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"pfctl -d, socketfilterfw --setglobalstate off, or modifications to com.apple.alf","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PFConfigFiles","description":"Monitor for baseline pf.conf and custom rule file modifications."}],"live":true,"detection_strategies":["DET0145"],"techniques":["T1686"]},{"id":"AN0409","stix_id":"x-mitre-analytic--1fecb6f7-e72f-452e-a078-3298cba8d481","name":"Analytic 0409","description":"Detection of firewall changes using esxcli network firewall set or vSphere API modifications. Sudden disabling of firewall rules across management interfaces is a strong adversarial signal.","url":"https://attack.mitre.org/detectionstrategies/DET0145#AN0409","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"esxcli network firewall set commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"},{"name":"esxi:hostd","channel":"vSphere API calls modifying firewall settings","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"APIMethods","description":"Whitelist of authorized vSphere API methods for firewall configuration."}],"live":true,"detection_strategies":["DET0145"],"techniques":["T1686"]},{"id":"AN0410","stix_id":"x-mitre-analytic--1216ae5e-bc5c-4672-a216-2706fb9ba3df","name":"Analytic 0410","description":"Detection of firewall ACL or rule base changes through CLI (e.g., no access-list, permit any any). Monitor configuration commits from unusual users or sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0145#AN0410","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:cli","channel":"firewall disable commands or suspicious ACL modifications","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"networkdevice-cli"}],"mutable_elements":[{"field":"AuthorizedAdmins","description":"List of approved admin accounts allowed to modify firewall ACLs."}],"live":true,"detection_strategies":["DET0145"],"techniques":["T1686"]}],"live":true,"version":"1.0","techniques":["T1686"]}],"sigma_rules":[{"id":"323ff3f5-0013-4847-bbd4-250b5edb62cc","title":"Modify System Firewall","author":"IAI","status":"test","level":"medium","date":"2023-03-06","modified":"2025-10-12","description":"Detects the removal of system firewall rules. Adversaries may only delete or modify a specific system firewall rule to bypass controls limiting network usage or access.\nDetection rules that match only on the disabling of firewalls will miss this.\n","references":["https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html","https://blog.aquasec.com/container-security-tnt-container-attack","https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/getting-started-with-nftables_configuring-and-managing-networking"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/auditd/execve/lnx_auditd_modify_system_firewall.yml","techniques":["T1686"],"cves":[]},{"id":"3be619f4-d9ec-4ea8-a173-18fdd01996ab","title":"Flush Iptables Ufw Chain","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","status":"test","level":"medium","date":"2023-01-18","modified":null,"description":"Detect use of iptables to flush all firewall rules, tables and chains and allow all network traffic","references":["https://blogs.blackberry.com/","https://www.cyberciti.biz/tips/linux-iptables-how-to-flush-all-rules.html","https://twitter.com/Joseliyo_Jstnk/status/1620131033474822144"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/process_creation/proc_creation_lnx_iptables_flush_ufw.yml","techniques":["T1686"],"cves":[]},{"id":"49f5dfc1-f92e-4d34-96fa-feba3f6acf36","title":"Disabling Security Tools - Builtin","author":"Ömer Günal, Alejandro Ortuno, oscd.community","status":"test","level":"medium","date":"2020-06-17","modified":"2022-11-26","description":"Detects disabling security tools","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.004/T1562.004.md"],"logsource":{"product":"linux","service":"syslog"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/builtin/syslog/lnx_syslog_security_tools_disabling_syslog.yml","techniques":["T1686"],"cves":[]},{"id":"53059bc0-1472-438b-956a-7508a94a91f0","title":"Disable System Firewall","author":"Pawel Mazur","status":"test","level":"high","date":"2022-01-22","modified":null,"description":"Detects disabling of system firewalls which could be used by adversaries to bypass controls that limit usage of the network.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.004/T1562.004.md","https://firewalld.org/documentation/man-pages/firewall-cmd.html"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/auditd/service_stop/lnx_auditd_disable_system_firewall.yml","techniques":["T1686"],"cves":[]},{"id":"70b4156e-50fc-4523-aa50-c9dddf1993fc","title":"Bpfdoor TCP Ports Redirect","author":"Rafal Piasecki","status":"test","level":"medium","date":"2022-08-10","modified":null,"description":"All TCP traffic on particular port from attacker is routed to different port. ex. '/sbin/iptables -t nat -D PREROUTING -p tcp -s 192.168.1.1 --dport 22 -j REDIRECT --to-ports 42392'\nThe traffic looks like encrypted SSH communications going to TCP port 22, but in reality is being directed to the shell port once it hits the iptables rule for the attacker host only.\n","references":["https://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/","https://www.elastic.co/security-labs/a-peek-behind-the-bpfdoor"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/auditd/execve/lnx_auditd_bpfdoor_port_redirect.yml","techniques":["T1686"],"cves":[]},{"id":"84c9e83c-599a-458a-a0cb-0ecce44e807a","title":"UFW Disable Attempt","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","status":"test","level":"medium","date":"2023-01-18","modified":"2026-05-04","description":"Detects attempts to disable the Uncomplicated Firewall (UFW) on Linux systems.\nUFW is a popular firewall management tool that provides an easy-to-use interface for configuring firewall rules.\nDisabling UFW can leave a system vulnerable to attacks, as it may allow unauthorized access to network services and resources.\n","references":["https://twitter.com/Joseliyo_Jstnk/status/1620131033474822144","https://manpages.debian.org/unstable/ufw/ufw-framework.8.en.html","https://www.cyberciti.biz/faq/linux-disable-firewall-command/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/process_creation/proc_creation_lnx_disable_ufw.yml","techniques":["T1686"],"cves":[]},{"id":"e3a8a052-111f-4606-9aee-f28ebeb76776","title":"Disabling Security Tools","author":"Ömer Günal, Alejandro Ortuno, oscd.community","status":"test","level":"medium","date":"2020-06-17","modified":"2022-10-09","description":"Detects disabling security tools","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.004/T1562.004.md"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1686"],"path":"rules/linux/process_creation/proc_creation_lnx_security_tools_disabling.yml","techniques":["T1686"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}