Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1686 Disable or Modify System Firewall |
GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| T1686 Disable or Modify System Firewall |
GroupBlackByte | BlackByte modified firewall rules on victim machines to enable remote system discovery. |
| T1686 Disable or Modify System Firewall |
GroupKimsuky | Kimsuky has been observed disabling the system firewall. |
| T1686 Disable or Modify System Firewall |
GroupSalt Typhoon | Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices. |
| T1686 Disable or Modify System Firewall |
GroupDragonfly | Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389. |
| T1686 Disable or Modify System Firewall |
GroupTeamTNT | TeamTNT has disabled |
| T1686 Disable or Modify System Firewall |
GroupFIN7 | FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898. |
| T1686 Disable or Modify System Firewall |
GroupRocke | Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers. |
| T1686 Disable or Modify System Firewall |
GroupUNC3886 | UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules. |
| T1686 Disable or Modify System Firewall |
GroupCarbanak | Carbanak may use netsh to add local firewall rule exceptions. |
| T1686 Disable or Modify System Firewall |
GroupMedusa Group | Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions. |
| T1686 Disable or Modify System Firewall |
GroupToddyCat | Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683. |
| T1686 Disable or Modify System Firewall |
GroupVelvet Ant | Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.