Modify System Firewall

 Original Source: [Sigma source]
Title: Modify System Firewall
Status: test
Description:Detects the removal of system firewall rules. Adversaries may only delete or modify a specific system firewall rule to bypass controls limiting network usage or access. Detection rules that match only on the disabling of firewalls will miss this.
References:
  -https://www.trendmicro.com/en_us/research/22/c/cyclops-blink-sets-sights-on-asus-routers--.html
  -https://blog.aquasec.com/container-security-tnt-container-attack
  -https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/getting-started-with-nftables_configuring-and-managing-networking
Author: IAI
Date: 2023-03-06
modified:2025-10-12
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection1:
    type: 'EXECVE'
    a0: 'iptables'
    a1|contains: 'DROP'
  selection2:
    type: 'EXECVE'
    a0: 'firewall-cmd'
    a1|contains: 'remove'
  selection3:
    type: 'EXECVE'
    a0: 'ufw'
    a1|contains: 'delete'
  selection4:
    type: 'EXECVE'
    a0: 'nft'
    a1|contains:
      -'delete'
      -'flush'

  condition:1 of selection*
Falsepositives:
  -Legitimate admin activity
Level: medium