ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1686.003×

9 examples

TechniqueUsed byProcedure example
T1686.003
Windows Host Firewall
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies the Windows firewall during execution.

T1686.003
Windows Host Firewall
MalwareDarkComet

DarkComet can disable Security Center functions like the Windows Firewall.

T1686.003
Windows Host Firewall
MalwareRemsec

Remsec can add or remove applications or ports on the Windows firewall or disable it entirely.

T1686.003
Windows Host Firewall
MalwareTYPEFRAME

TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections.

T1686.003
Windows Host Firewall
MalwareBADCALL

BADCALL disables the Windows firewall before binding to a port.

T1686.003
Windows Host Firewall
MalwareHiddenFace

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.

T1686.003
Windows Host Firewall
MalwareHARDRAIN

HARDRAIN opens the Windows Firewall to modify incoming connections.

T1686.003
Windows Host Firewall
MalwarenjRAT

njRAT has modified the Windows firewall to allow itself to communicate through the firewall.

T1686.003
Windows Host Firewall
MalwareH1N1

H1N1 kills and disables services for Windows Firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.