Impair Defenses: Disable or Modify System Firewall T1562.004
Tactic: Stealth
Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage. Changes could be disabling the entire mechanism as well as adding, deleting, or modifying particular rules. This can be done numerous ways depending on the operating system, including via command-line, editing Windows Registry keys, and Windows Control Panel.
Events covered
12 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 25 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (35 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (366 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 11 rules
- Firewall deactivation (deprecated command)
- Firewall deactivation (firewall)
- Firewall deactivation (modern command)
- Firewall deactivation (PowerShell)
- Firewall Disabled
- Firewall rule added using PowerShell or CMD
- Firewall rule any/any created
- Firewall rule creation (command)
- OpenSSH server firewall configuration on Windows (command)
- OpenSSH server firewall configuration on Windows (firewall)
- OpenSSH server firewall configuration on Windows (PowerShell)
Elastic 6 rules
- Attempt to Disable IPTables or Firewall
- Disable Windows Firewall Rules via Netsh
- Enable Host Network Discovery via Netsh
- Potential Evasion via Windows Filtering Platform
- Remote Desktop Enabled in Windows Firewall by Netsh
- Windows Firewall Disabled via PowerShell
Splunk 5 rules
- Windows Firewall Disabled (PowerShell)
- Windows Firewall Disabled (Sysmon)
- Windows Firewall Disabled (Windows Event Log)
- Windows Firewall Rule Creation (PowerShell)
- Windows Firewall Rule Creation (Windows Event Log)