Disable or Modify System Firewall

T1686

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.

Adversaries may disable or modify firewalls using different behaviors, depending on the platform. For example, in ESXi, firewall rules may be modified directly via the esxcli (e.g., via esxcli network firewall set) or via the vCenter user interface.

Detection rules50

Rules on DetectionCode tagged with T1686 or one of its sub-techniques.

Sigma31

RuleLevelLog sourceTechnique
All Rules Have Been Deleted From The Windows Firewall Configurationhighwindows / NULLT1686.003
Disable System Firewallhighlinux / NULLT1686
New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Applicationhighwindows / NULLT1686.003
RDP Connection Allowed Via Netsh.EXEhighwindows / process_creationT1686.003
Suspicious Program Location Whitelisted In Firewall Via Netsh.EXEhighwindows / process_creationT1686.003
A Rule Has Been Deleted From The Windows Firewall Exception Listmediumwindows / NULLT1686.003
Azure Firewall Modified or Deletedmediumazure / NULLT1686.001
Azure Firewall Rule Collection Modified or Deletedmediumazure / NULLT1686.001
Azure Network Firewall Policy Modified or Deletedmediumazure / NULLT1686.001
Bpfdoor TCP Ports Redirectmediumlinux / NULLT1686
Disable Microsoft Defender Firewall via Registrymediumwindows / registry_setT1686.003
Disable Windows Firewall by Registrymediumwindows / registry_setT1686.003
Disabling Security Toolsmediumlinux / process_creationT1686
Disabling Security Tools - Builtinmediumlinux / NULLT1686
Firewall Disabled via Netsh.EXEmediumwindows / process_creationT1686.003

Splunk19

RuleTypeRiskData sourceTechnique
Allow File And Printing Sharing In FirewallTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1686.001
Allow Network Discovery In FirewallTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1686.001
ASL AWS Network Access Control List Created with All Open PortsTTPNULLASL AWS CloudTrailT1686.001
ASL AWS Network Access Control List DeletedAnomalyNULLASL AWS CloudTrailT1686.001
AWS Network Access Control List Created with All Open PortsTTPNULLAWS CloudTrail CreateNetworkAclEntry, AWS CloudTrail ReplaceNetworkAclEntryT1686.001
AWS Network Access Control List DeletedAnomalyNULLAWS CloudTrail DeleteNetworkAclEntryT1686.001
ESXi Firewall DisabledTTPNULLVMWare ESXi SyslogT1686
Firewall Allowed Program EnableAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1686
Linux Auditd Disable Or Modify System FirewallAnomalyNULLLinux Auditd Service StopT1686
Linux Iptables Firewall ModificationAnomalyNULLSysmon for Linux EventID 1T1686
Linux Stdout Redirection To Dev Null FileAnomalyNULLSysmon for Linux EventID 1T1686
Microsoft Intune DeviceManagementConfigurationPoliciesHuntingNULLAzure Monitor ActivityT1686
O365 Bypass MFA via Trusted IPTTPNULLO365 Set Company Information.T1686.001
Processes launching netshAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1686
Windows Delete or Modify System FirewallHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1686

Sub-techniques3

IDNameExamples
T1686.001Cloud Firewall1
T1686.002Network Device Firewall4
T1686.003Windows Host Firewall17

Groups13

Software15

Campaigns2

Procedure examples30

Groups13

Used byProcedure example
GroupAPT38

APT38 have created firewall exemptions on specific ports, including ports 443, 6443, 8443, and 9443.

GroupBlackByte

BlackByte modified firewall rules on victim machines to enable remote system discovery.

GroupCarbanak

Carbanak may use netsh to add local firewall rule exceptions.

GroupDragonfly

Dragonfly has disabled host-based firewalls. The group has also globally opened port 3389.

GroupFIN7

FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898.

GroupKimsuky

Kimsuky has been observed disabling the system firewall.

GroupMedusa Group

Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings. Medusa Group has also enabled and modified firewall rules to allow for RDP connections for lateral movement and device interactions.

GroupRocke

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.

View all 13 groups examples

Software15

Used byProcedure example
MalwareBACKSPACE

The "ZR" variant of BACKSPACE will check to see if known host-based firewalls are installed on the infected systems. BACKSPACE will attempt to establish a C2 channel, then will examine open windows to identify a pop-up from the firewall software and will simulate a mouse-click to allow the connection to proceed.

MalwareBPFDoor

BPFDoor starts a shell on a high TCP port starting at 42391 up to 43391, then changes the local `iptables` rules to redirect all packets from the attacker to the shell port.

MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

MalwareGrandoreiro

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.

MalwareHannotog

Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port.

MalwareHOPLIGHT

HOPLIGHT has modified the firewall using netsh.

MalwareInvisiMole

InvisiMole has a command to disable routing and the Firewall on the victim’s machine.

MalwareKasidet

Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded.

View all 15 software examples

Campaigns2

Used byProcedure example
CampaignLeviathan Australian Intrusions

Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets.

References3

  1. Broadcom ESXi Firewall Open source
    Broadcom. (2025, March 24). Add Allowed IP Addresses for an ESXi Host by Using the VMware Host Client. Retrieved March 26, 2025.
  2. Trellix Rnasomhouse 2024 Open source
    Pham Duy Phuc, Max Kersten, Noël Keijzer, and Michaël Schrijver. (2024, February 14). RansomHouse am See. Retrieved March 26, 2025.
  3. change_rdp_port_conti Open source
    The DFIR Report. (2022, March 1). "Change RDP port" #ContiLeaks. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.