Sub-technique of T1686 Disable or Modify System Firewall.View on attack.mitre.org
Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage.
Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic. For example, adversaries may add new network firewall rules to allow access to all internal network subnets without restrictions. Allowing access to internal network subsets may enable unrestricted inbound/outbound connectivity or open paths for command and control and lateral movement.
Adversaries may obtain access to network device management interfaces via Valid Accounts or by exploiting vulnerabilities. In some cases, threat actors may target firewalls and other network infrastructure that are exposed to the internet by leveraging weaknesses in public-facing applications (Exploit Public-Facing Application).
Adversaries may also modify host networking configurations that indirectly manipulate system firewalls, such as adjusting interface bandwidth or network connection request thresholds.
Rules on DetectionCode tagged with T1686.002.
| Rule | Level | Log source |
|---|---|---|
| FortiGate - Firewall Address Object Added | medium | fortigate / NULL |
| FortiGate - New Firewall Policy Added | medium | fortigate / NULL |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443. |
| Used by | Procedure example |
|---|---|
| MalwareCyclops Blink | Cyclops Blink can modify the Linux iptables firewall to enable C2 communication on network devices via a stored list of port numbers. |
| MalwareGrandoreiro | Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified security settings within the victims Fortigate device, utilizing the native CLI. During the 2025 Poland Wiper Attacks, the adversaries also disabled network traffic logging. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.