ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1686×

15 examples

TechniqueUsed byProcedure example
T1686
Disable or Modify System Firewall
MalwareKasidet

Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded.

T1686
Disable or Modify System Firewall
MalwareHannotog

Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port.

T1686
Disable or Modify System Firewall
MalwarePyDCrypt

PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines.

T1686
Disable or Modify System Firewall
MalwareTHINCRUST

THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections.

T1686
Disable or Modify System Firewall
MalwareShrinkLocker

ShrinkLocker turns on the system firewall and deletes all of its rules during execution.

T1686
Disable or Modify System Firewall
MalwareHOPLIGHT

HOPLIGHT has modified the firewall using netsh.

T1686
Disable or Modify System Firewall
MalwareInvisiMole

InvisiMole has a command to disable routing and the Firewall on the victim’s machine.

T1686
Disable or Modify System Firewall
MalwarePlugX

PlugX has modified local firewall rules on victim machines to enable a random, high-number listening port for subsequent access and C2 activity.

T1686
Disable or Modify System Firewall
MalwareBPFDoor

BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port.

T1686
Disable or Modify System Firewall
MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

T1686
Disable or Modify System Firewall
MalwareNanoCore

NanoCore can modify the victim's firewall.

T1686
Disable or Modify System Firewall
MalwareZxShell

ZxShell can disable the firewall by modifying the registry key HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile.

T1686
Disable or Modify System Firewall
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1686
Disable or Modify System Firewall
MalwareBACKSPACE

The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed.

T1686
Disable or Modify System Firewall
Toolnetsh

netsh can be used to disable local firewall settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.