Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1685.005 Clear Windows Event Logs |
MalwareQilin | Qilin has the ability to clear Windows Event Logs. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWizard | HermeticWizard has the ability to use `wevtutil cl system` to clear event logs. |
| T1685.005 Clear Windows Event Logs |
ToolPupy | Pupy has a module to clear event logs with PowerShell. |
| T1685.005 Clear Windows Event Logs |
ToolWevtutil | Wevtutil can be used to clear system and security event logs from the system. |
| T1685.006 Clear Linux or Mac System Logs |
GroupSalt Typhoon | Salt Typhoon has cleared logs including .bash_history, auth.log, lastlog, wtmp, and btmp. |
| T1685.006 Clear Linux or Mac System Logs |
GroupTeamTNT | TeamTNT has removed system logs from |
| T1685.006 Clear Linux or Mac System Logs |
GroupRocke | Rocke has cleared log files within the /var/log/ folder. |
| T1685.006 Clear Linux or Mac System Logs |
GroupSea Turtle | Sea Turtle has overwritten Linux system logs and unsets the Bash history file (effectively removing logging) during intrusions. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareJumbledPath | JumbledPath can clear logs on all devices used along its connection path to compromised network infrastructure. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareUPSTYLE | UPSTYLE clears error logs after reading embedded commands for execution. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareMacMa | MacMa can clear possible malware traces such as application logs. |
| T1685.006 Clear Linux or Mac System Logs |
MalwareProton | Proton removes logs from |
| T1686 Disable or Modify System Firewall |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets. |
| T1686 Disable or Modify System Firewall |
CampaignLeviathan Australian Intrusions | Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions. |
| T1686 Disable or Modify System Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686 Disable or Modify System Firewall |
GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
| T1686 Disable or Modify System Firewall |
GroupKimsuky | Kimsuky has been observed disabling the system firewall. |
| T1686 Disable or Modify System Firewall |
GroupSalt Typhoon | Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices. |
| T1686 Disable or Modify System Firewall |
GroupDragonfly | Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389. |
| T1686 Disable or Modify System Firewall |
GroupTeamTNT | TeamTNT has disabled |
| T1686 Disable or Modify System Firewall |
GroupFIN7 | FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898. |
| T1686 Disable or Modify System Firewall |
GroupRocke | Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
| T1686 Disable or Modify System Firewall |
GroupCarbanak | Carbanak may use netsh to add local firewall rule exceptions. |
| T1686 Disable or Modify System Firewall |
GroupMedusa Group | Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions. |
| T1686 Disable or Modify System Firewall |
GroupToddyCat | Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683. |
| T1686 Disable or Modify System Firewall |
GroupVelvet Ant | Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices. |
| T1686 Disable or Modify System Firewall |
MalwareKasidet | Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded. |
| T1686 Disable or Modify System Firewall |
MalwareHannotog | Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port. |
| T1686 Disable or Modify System Firewall |
MalwarePyDCrypt | PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines. |
| T1686 Disable or Modify System Firewall |
MalwareTHINCRUST | THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections. |
| T1686 Disable or Modify System Firewall |
MalwareShrinkLocker | ShrinkLocker turns on the system firewall and deletes all of its rules during execution. |
| T1686 Disable or Modify System Firewall |
MalwareHOPLIGHT | |
| T1686 Disable or Modify System Firewall |
MalwareInvisiMole | InvisiMole has a command to disable routing and the Firewall on the victim’s machine. |
| T1686 Disable or Modify System Firewall |
MalwarePlugX | PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity. |
| T1686 Disable or Modify System Firewall |
MalwareBPFDoor | BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port. |
| T1686 Disable or Modify System Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| T1686 Disable or Modify System Firewall |
MalwareNanoCore | NanoCore can modify the victim's firewall. |
| T1686 Disable or Modify System Firewall |
MalwareZxShell | ZxShell can disable the firewall by modifying the registry key |
| T1686 Disable or Modify System Firewall |
MalwareCookieMiner | CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found. |
| T1686 Disable or Modify System Firewall |
MalwareBACKSPACE | The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed. |
| T1686 Disable or Modify System Firewall |
Toolnetsh | netsh can be used to disable local firewall settings. |
| T1686.001 Cloud Firewall |
ToolPacu | Pacu can allowlist IP addresses in AWS GuardDuty. |
| T1686.002 Network Device Firewall |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified security settings within the victims Fortigate device, utilizing the native CLI. During the 2025 Poland Wiper Attacks, the adversaries also disabled network traffic logging. |
| T1686.002 Network Device Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686.002 Network Device Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| T1686.002 Network Device Firewall |
MalwareCyclops Blink | Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers. |
| T1686.003 Windows Host Firewall |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 added rules to a victim's Windows firewall to set up a series of port-forwards allowing traffic to target systems. |
| T1686.003 Windows Host Firewall |
CampaignOperation Wocao | During Operation Wocao, threat actors used PowerShell to add and delete rules in the Windows firewall. |
| T1686.003 Windows Host Firewall |
GroupMoses Staff | Moses Staff has used batch scripts that can disable the Windows firewall on specific remote machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.