Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1686 Disable or Modify System Firewall |
MalwareKasidet | Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded. |
| T1686 Disable or Modify System Firewall |
MalwareHannotog | Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port. |
| T1686 Disable or Modify System Firewall |
MalwarePyDCrypt | PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines. |
| T1686 Disable or Modify System Firewall |
MalwareTHINCRUST | THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections. |
| T1686 Disable or Modify System Firewall |
MalwareShrinkLocker | ShrinkLocker turns on the system firewall and deletes all of its rules during execution. |
| T1686 Disable or Modify System Firewall |
MalwareHOPLIGHT | |
| T1686 Disable or Modify System Firewall |
MalwareInvisiMole | InvisiMole has a command to disable routing and the Firewall on the victim’s machine. |
| T1686 Disable or Modify System Firewall |
MalwarePlugX | PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity. |
| T1686 Disable or Modify System Firewall |
MalwareBPFDoor | BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port. |
| T1686 Disable or Modify System Firewall |
MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| T1686 Disable or Modify System Firewall |
MalwareNanoCore | NanoCore can modify the victim's firewall. |
| T1686 Disable or Modify System Firewall |
MalwareZxShell | ZxShell can disable the firewall by modifying the registry key |
| T1686 Disable or Modify System Firewall |
MalwareCookieMiner | CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found. |
| T1686 Disable or Modify System Firewall |
MalwareBACKSPACE | The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed. |
| T1686 Disable or Modify System Firewall |
Toolnetsh | netsh can be used to disable local firewall settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.