Sub-technique of T1686 Disable or Modify System Firewall.View on attack.mitre.org
Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary with appropriate permissions may introduce new firewall rules or policies to allow access into a victim cloud environment and/or move laterally from the cloud control plane to the data plane.
For example, an adversary may use a script or utility that creates new ingress rules in existing security groups (or creates new security groups entirely) to allow any TCP/IP connectivity to a cloud-hosted instance. They may also remove networking limitations to support traffic associated with malicious activity (such as cryptomining).
Rules on DetectionCode tagged with T1686.001.
| Rule | Level | Log source |
|---|---|---|
| Azure Firewall Modified or Deleted | medium | azure / NULL |
| Azure Firewall Rule Collection Modified or Deleted | medium | azure / NULL |
| Azure Network Firewall Policy Modified or Deleted | medium | azure / NULL |
| New Network Route Added | medium | aws / NULL |
| New Network ACL Entry Added | low | aws / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Allow File And Printing Sharing In Firewall | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Allow Network Discovery In Firewall | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| ASL AWS Network Access Control List Created with All Open Ports | TTP | NULL | ASL AWS CloudTrail |
| ASL AWS Network Access Control List Deleted | Anomaly | NULL | ASL AWS CloudTrail |
| AWS Network Access Control List Created with All Open Ports | TTP | NULL | AWS CloudTrail CreateNetworkAclEntry, AWS CloudTrail ReplaceNetworkAclEntry |
| AWS Network Access Control List Deleted | Anomaly | NULL | AWS CloudTrail DeleteNetworkAclEntry |
| O365 Bypass MFA via Trusted IP | TTP | NULL | O365 Set Company Information. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.