Cloud Firewall

T1686.001

Sub-technique of T1686 Disable or Modify System Firewall.View on attack.mitre.org

About this technique

Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.

Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary with appropriate permissions may introduce new firewall rules or policies to allow access into a victim cloud environment and/or move laterally from the cloud control plane to the data plane.

For example, an adversary may use a script or utility that creates new ingress rules in existing security groups (or creates new security groups entirely) to allow any TCP/IP connectivity to a cloud-hosted instance. They may also remove networking limitations to support traffic associated with malicious activity (such as cryptomining).

Detection rules12

Rules on DetectionCode tagged with T1686.001.

Sigma5

Splunk7

RuleTypeRiskData source
Allow File And Printing Sharing In FirewallTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Allow Network Discovery In FirewallTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
ASL AWS Network Access Control List Created with All Open PortsTTPNULLASL AWS CloudTrail
ASL AWS Network Access Control List DeletedAnomalyNULLASL AWS CloudTrail
AWS Network Access Control List Created with All Open PortsTTPNULLAWS CloudTrail CreateNetworkAclEntry, AWS CloudTrail ReplaceNetworkAclEntry
AWS Network Access Control List DeletedAnomalyNULLAWS CloudTrail DeleteNetworkAclEntry
O365 Bypass MFA via Trusted IPTTPNULLO365 Set Company Information.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
ToolPacu

Pacu can allowlist IP addresses in AWS GuardDuty.

References2

  1. Expel AWS Open source
    Anthony Randazzo, Britton Manahan, Sam Lipton. (2020, April 28). Managed Detection & Response for AWS. Retrieved April 15, 2026.
  2. Palo Alto Unit 42 Compromised Cloud Compute Credentials 2022 Open source
    Dror Alon. (2022, December 8). Compromised Cloud Compute Credentials: Case Studies From the Wild. Retrieved March 9, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.