Disable or Modify System Firewall T1686
Tactic: Defense Impairment
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.
Events covered
33 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 133 rules share fields, values, and exclusions.
Fields filtered most (95 distinct)
These fields appear most often in rule filters.
Top indicator values (734 distinct)
These values appear most often in rule predicates.
Exclusions (59 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 59 rules
- A Rule Has Been Deleted From The Windows Firewall Exception List
- All Rules Have Been Deleted From The Windows Firewall Configuration
- Attack protection features manipulation - some attack protection features have been disabled.
- Azure Firewall Modified or Deleted
- Azure Firewall Rule Collection Modified or Deleted
- Azure Network Firewall Policy Modified or Deleted
- Bot detection - the feature is turned off completely or some policies.
- Bpfdoor TCP Ports Redirect
- Breached Password Detection - critical settings manipulated
- Brute Force Protection - critical settings manipulated
- Disable Microsoft Defender Firewall via Registry
- Disable System Firewall
- Disable Windows Firewall by Registry
- Disabling Security Tools
- Disabling Security Tools - Builtin
- Excessive or unexpected Management API scope grants on applications
- Firewall deactivation (deprecated command)
- Firewall deactivation (firewall)
- Firewall deactivation (modern command)
- Firewall deactivation (PowerShell)
- Firewall Disabled
- Firewall Disabled via Netsh.EXE
- Firewall rule added using PowerShell or CMD
- Firewall rule any/any created
- Firewall rule creation (command)
- Firewall Rule Deleted Via Netsh.EXE
- Firewall Rule Modified In The Windows Firewall Exception List
- Flush Iptables Ufw Chain
- FortiGate - Firewall Address Object Added
- FortiGate - New Firewall Policy Added
- Insecure OAuth2.x flows have been enabled for some applications
- Loaded LiquidJS error page template contains XSS vulnerabilities
- MFA downgrade - adaptive MFA risk assessment disabled
- MFA downgrade - disable MFA policies by modifying the policies
- MFA downgrade - disable strong factors
- Modify System Firewall
- Netsh Allow Group Policy on Microsoft Defender Firewall
- New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
- New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
- New Firewall Rule Added Via Netsh.EXE
- New Network ACL Entry Added
- New Network Route Added
- New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet
- New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet - ScriptBlock
- OpenSSH server firewall configuration on Windows (command)
- OpenSSH server firewall configuration on Windows (firewall)
- OpenSSH server firewall configuration on Windows (PowerShell)
- RDP Connection Allowed Via Netsh.EXE
- Risk for misconfiguration - use of Auth0 tenant name URL.
- Suspicious IP Throttling - critical settings manipulated
- Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
- The Windows Defender Firewall Service Failed To Load Group Policy
- UFW Disable Attempt
- Unauthorized or Unexpected Enabling of Cross-Origin Authentication (CORS)
- Uncommon New Firewall Rule Added In Windows Firewall Exception List
- Unrecognized IP in attack protection allowlists
- Windows Defender Firewall Has Been Reset To Its Default Configuration
- Windows Firewall Profile Disabled
- Windows Firewall Settings Have Been Changed
Elastic 32 rules
- Attempt to Deactivate an Okta Network Zone
- Attempt to Deactivate an Okta Policy
- Attempt to Deactivate an Okta Policy Rule
- Attempt to Delete an Okta Network Zone
- Attempt to Delete an Okta Policy
- Attempt to Delete an Okta Policy Rule
- Attempt to Disable IPTables or Firewall
- Attempt to Modify an Okta Network Zone
- Attempt to Modify an Okta Policy
- Attempt to Modify an Okta Policy Rule
- AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity
- AWS EC2 Network Access Control List Creation
- AWS EC2 Network Access Control List Deletion
- AWS EC2 Security Group Configuration Change
- AWS WAF Access Control List Deletion
- AWS WAF Rule or Rule Group Deletion
- Azure VNet Firewall Front Door WAF Policy Deleted
- Azure VNet Firewall Policy Deleted
- Disable Windows Firewall Rules via Netsh
- Domain Added to Google Workspace Trusted Domains
- Enable Host Network Discovery via Netsh
- GCP Firewall Rule Creation
- GCP Firewall Rule Deletion
- GCP Firewall Rule Modification
- GCP Virtual Private Cloud Network Deletion
- GCP Virtual Private Cloud Route Creation
- GCP Virtual Private Cloud Route Deletion
- Insecure AWS EC2 VPC Security Group Ingress Rule Added
- Potential Evasion via Windows Filtering Platform
- Remote Desktop Enabled in Windows Firewall by Netsh
- Windows Firewall Disabled via PowerShell
- Windows Firewall Exception List Modified via Untrusted Process
Splunk 24 rules
- Allow File And Printing Sharing In Firewall
- Allow Network Discovery In Firewall
- ASL AWS Network Access Control List Created with All Open Ports
- ASL AWS Network Access Control List Deleted
- AWS Network Access Control List Created with All Open Ports
- AWS Network Access Control List Deleted
- ESXi Firewall Disabled
- Firewall Allowed Program Enable
- Linux Auditd Disable Or Modify System Firewall
- Linux Iptables Firewall Modification
- Linux Stdout Redirection To Dev Null File
- Microsoft Intune DeviceManagementConfigurationPolicies
- O365 Bypass MFA via Trusted IP
- Windows Delete or Modify System Firewall
- Windows Firewall Disabled (PowerShell)
- Windows Firewall Disabled (Sysmon)
- Windows Firewall Disabled (Windows Event Log)
- Windows Firewall Rule Added
- Windows Firewall Rule Creation (PowerShell)
- Windows Firewall Rule Creation (Sysmon)
- Windows Firewall Rule Creation (Windows Event Log)
- Windows Firewall Rule Deletion
- Windows Firewall Rule Modification
- Windows Modify System Firewall with Notable Process Path
Kusto 11 rules
- AWSCloudTrail - Changes to Amazon VPC settings
- AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups
- AWSCloudTrail - Changes to AWS Security Group ingress and egress settings
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Network ACL with all the open ports to a specified CIDR
- Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed)
- Conditional Access - A Conditional Access policy was deleted
- Conditional Access - A Conditional Access policy was disabled
- Conditional Access - A Conditional Access policy was put into report-only mode
- Conditional Access - A new Conditional Access policy was created
- GCP Audit Logs - Open Firewall Rule Created or Modified