Disable or Modify System Firewall T1686

Tactic: Defense Impairment

Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.

Events covered

33 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 13RegistryEvent (Value Set)
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4946A change has been made to Windows Firewall exception list. A rule was added.
Security-AuditingEvent ID 4947A change has been made to Windows Firewall exception list. A rule was modified.
Security-AuditingEvent ID 4948A change has been made to Windows Firewall exception list. A rule was deleted.
Security-AuditingEvent ID 4950A Windows Firewall setting has changed.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Linux-AuditdEvent ID 1131SERVICE_STOP
Linux-AuditdEvent ID 1309EXECVE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
Windows-Firewall-With-Advanced-SecurityEvent ID 2002A Windows Defender Firewall setting has changed.
Windows-Firewall-With-Advanced-SecurityEvent ID 2003A Windows Defender Firewall setting in the Profiles profile has changed.
Windows-Firewall-With-Advanced-SecurityEvent ID 2004A rule has been added to the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2005A rule has been modified in the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2006A rule has been deleted in the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2008Windows Defender Firewall Group Policy settings have changed.
Windows-Firewall-With-Advanced-SecurityEvent ID 2009The Windows Defender Firewall service failed to load Group Policy.
Windows-Firewall-With-Advanced-SecurityEvent ID 2032Windows Defender Firewall has been reset to its default configuration.
Windows-Firewall-With-Advanced-SecurityEvent ID 2033All rules have been deleted from the Windows Defender Firewall configuration on this computer.
Windows-Firewall-With-Advanced-SecurityEvent ID 2052A rule has been deleted in the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2059All rules have been deleted from the Windows Defender Firewall configuration on this computer.
Windows-Firewall-With-Advanced-SecurityEvent ID 2060Windows Defender Firewall has been reset to its default configuration.
Windows-Firewall-With-Advanced-SecurityEvent ID 2071A rule has been added to the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2073A rule has been modified in the Windows Defender Firewall exception list.
Windows-Firewall-With-Advanced-SecurityEvent ID 2082A Windows Defender Firewall setting in the Profiles profile has changed.
Windows-Firewall-With-Advanced-SecurityEvent ID 2083A Windows Defender Firewall setting has changed.
Windows-Firewall-With-Advanced-SecurityEvent ID 2097A rule has been added to the Windows Defender Firewall exception list.
PowerShellEvent ID 800Event ID 800
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 133 rules share fields, values, and exclusions.

Fields filtered most (95 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType26eq 15, in 7, wildcard 6, ends_with 3authorizesecuritygroupingress, createnetworkaclentry, start, .compute.firewalls.delete, .compute.firewalls.insert
data_stream.dataset25eq 25okta.system, aws.cloudtrail, gcp.audit, azure.activitylogs, google_workspace.admin
CommandLine22contains 21, in 1, match 1, wildcard 1firewall, advfirewall, allow, firewall , add
Image14ends_with 13, starts_with 1\netsh.exe, /chkconfig, /ip6tables, /ip6tables-legacy-multi, /iptables
aws::eventName14eq 8, in 6createnetworkaclentry, deletenetworkaclentry, replacenetworkaclentry, AuthorizeDBSecurityGroupIngress, CreateNetworkAclEntry
data.type13eq 13sapi, f, fcoa, fepft
process_name13eq 10, regex_match 3, in 1netsh.exe, (?i)cmd|powershell|netsh|net1?|sc.exe|reg.exe, almon.exe, alsvc.exe, alupdate.exe
OriginalFileName12eq 11, in 1netsh.exe, powershell.exe, pwsh.dll, powershell_ise.exe
data.description11eq 11create or update the anomaly detection captcha, update brute-force settings, update suspicious ip throttling settings, update a client, update breached password detection settings
event.outcome11eq 10, in 1success, failure
EventID8eq 84104, 4688, 4103, 4946, 4947
sourcetype8eq 7, in 1aws:asl, aws:cloudtrail, auditd, azure:monitor:activity, o365:management:activity
Provider_Name7eq 5, in 2ec2.amazonaws.com, waf-regional.amazonaws.com, waf.amazonaws.com, wafv2.amazonaws.com
host.os.type6eq 6
operationName6eq 4, contains 1, in 1microsoft.network/firewallpolicies/delete, devicemanagementconfigurationpolicy, microsoft.network/azurefirewalls/applicationrulecollectio..., microsoft.network/azurefirewalls/applicationrulecollections/write, microsoft.network/azurefirewalls/delete

Top indicator values (734 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
data.typeeq
sapi
1218
CommandLinecontains
firewall
1113
CommandLinecontains
advfirewall
57
CommandLinecontains
add
434
CommandLinecontains
allow
46
CommandLinecontains
disable
413
CommandLinecontains
netsh
49
CommandLinecontains
set
411
CommandLinecontains
enable
33
CommandLinecontains
off
34
OriginalFileNameeq
netsh.exe
1023
event.outcomeeq
success
10369
Imageends_with
\netsh.exe
928
data_stream.dataseteq
okta.system
948
data_stream.dataseteq
aws.cloudtrail
7169
data_stream.dataseteq
gcp.audit
669
process_nameeq
netsh.exe
721
Provider_Nameeq
ec2.amazonaws.com
520
event.typeeq
start
51078
data.details.response.body.enabledeq
false
45
OperationNameeq
Update conditional access policy
36
aws::eventNameeq
createnetworkaclentry
33
data.descriptioneq
create or update the anomaly detection captcha
33
data.descriptioneq
update brute-force settings
33
data.descriptioneq
update suspicious ip throttling settings
33
data.details.response.statusCodeeq
200
35
egresseq
false
33
process_nameregex_match
(?i)cmd|powershell|netsh|net1?|sc.exe|reg.exe
33
Actioneq
2
2
Actioneq
3
22

Exclusions (59 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Actioneq
2
2
ModifyingApplicationends_with
\MsMpEng.exe
2
ModifyingApplicationeq
c:\windows\system32\svchost.exe
2
ModifyingApplicationstarts_with
C:\ProgramData\Microsoft\Windows Defender\Platform\
2
ModifyingApplicationstarts_with
C:\Windows\WinSxS\
2
data.details.response.body.shields{}eq
block
2
ApplicationPathcontains
:\users\
1
ApplicationPathcontains
\appdata\local\bravesoftware\brave-browser\application\brave.exe
1
ApplicationPathcontains
\appdata\local\programs\opera\
1
ApplicationPathcontains
\appdata\local\temp\
1
ApplicationPathcontains
\opera.exe
1
ApplicationPathcontains
c:\perflogs\
1
ApplicationPathcontains
c:\temp\
1
ApplicationPathcontains
c:\tmp\
1
ApplicationPathcontains
c:\users\public\
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 59 rules

Elastic 32 rules

Splunk 24 rules

Kusto 11 rules

YARA-L 1 rule

Panther 6 rules