Impair Defenses: Disable or Modify Cloud Firewall T1562.007
Tactic: Stealth
Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud firewalls are separate from system firewalls that are described in Disable or Modify System Firewall.
Authoring guide
Patterns shared across the 53 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (43 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (146 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (3 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 14 rules
- Attack protection features manipulation - some attack protection features have been disabled.
- Bot detection - the feature is turned off completely or some policies.
- Breached Password Detection - critical settings manipulated
- Brute Force Protection - critical settings manipulated
- Excessive or unexpected Management API scope grants on applications
- Insecure OAuth2.x flows have been enabled for some applications
- Loaded LiquidJS error page template contains XSS vulnerabilities
- MFA downgrade - adaptive MFA risk assessment disabled
- MFA downgrade - disable MFA policies by modifying the policies
- MFA downgrade - disable strong factors
- Risk for misconfiguration - use of Auth0 tenant name URL.
- Suspicious IP Throttling - critical settings manipulated
- Unauthorized or Unexpected Enabling of Cross-Origin Authentication (CORS)
- Unrecognized IP in attack protection allowlists
Elastic 24 rules
- Attempt to Deactivate an Okta Network Zone
- Attempt to Deactivate an Okta Policy
- Attempt to Deactivate an Okta Policy Rule
- Attempt to Delete an Okta Network Zone
- Attempt to Delete an Okta Policy
- Attempt to Delete an Okta Policy Rule
- Attempt to Modify an Okta Network Zone
- Attempt to Modify an Okta Policy
- Attempt to Modify an Okta Policy Rule
- AWS EC2 Network Access Control List Creation
- AWS EC2 Network Access Control List Deletion
- AWS EC2 Security Group Configuration Change
- AWS WAF Access Control List Deletion
- AWS WAF Rule or Rule Group Deletion
- Azure VNet Firewall Front Door WAF Policy Deleted
- Azure VNet Firewall Policy Deleted
- Domain Added to Google Workspace Trusted Domains
- GCP Firewall Rule Creation
- GCP Firewall Rule Deletion
- GCP Firewall Rule Modification
- GCP Virtual Private Cloud Network Deletion
- GCP Virtual Private Cloud Route Creation
- GCP Virtual Private Cloud Route Deletion
- Insecure AWS EC2 VPC Security Group Ingress Rule Added
Kusto 10 rules
- AWSCloudTrail - Changes to Amazon VPC settings
- AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups
- AWSCloudTrail - Changes to AWS Security Group ingress and egress settings
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Network ACL with all the open ports to a specified CIDR
- Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed)
- Conditional Access - A Conditional Access policy was deleted
- Conditional Access - A Conditional Access policy was disabled
- Conditional Access - A Conditional Access policy was put into report-only mode
- Conditional Access - A new Conditional Access policy was created