ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1686×

13 examples

TechniqueUsed byProcedure example
T1686
Disable or Modify System Firewall
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

T1686
Disable or Modify System Firewall
GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

T1686
Disable or Modify System Firewall
GroupKimsuky

Kimsuky has been observed disabling the system firewall.

T1686
Disable or Modify System Firewall
GroupSalt Typhoon

Salt Typhoon has made changes to the Access Control List (ACL) and loopback interface address on compromised devices.

T1686
Disable or Modify System Firewall
GroupDragonfly

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.

T1686
Disable or Modify System Firewall
GroupTeamTNT

TeamTNT has disabled iptables.

T1686
Disable or Modify System Firewall
GroupFIN7

FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898.

T1686
Disable or Modify System Firewall
GroupRocke

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.

T1686
Disable or Modify System Firewall
GroupUNC3886

UNC3886 has used the TABLEFLIP traffic redirection utility and the esxcli command line to modify firewall rules.

T1686
Disable or Modify System Firewall
GroupCarbanak

Carbanak may use netsh to add local firewall rule exceptions.

T1686
Disable or Modify System Firewall
GroupMedusa Group

Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions.

T1686
Disable or Modify System Firewall
GroupToddyCat

Prior to executing a backdoor ToddyCat has run `cmd /c start /b netsh advfirewall firewall add rule name="SGAccessInboundRule" dir=in protocol=udp action=allow localport=49683` to allow the targeted system to receive UDP packets on port 49683.

T1686
Disable or Modify System Firewall
GroupVelvet Ant

Velvet Ant modified system firewall settings during PlugX installation using `netsh.exe` to open a listening, random high number port on victim devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.