Flush Iptables Ufw Chain

 Original Source: [Sigma source]
Title: Flush Iptables Ufw Chain
Status: test
Description:Detect use of iptables to flush all firewall rules, tables and chains and allow all network traffic
References:
  -https://blogs.blackberry.com/
  -https://www.cyberciti.biz/tips/linux-iptables-how-to-flush-all-rules.html
  -https://twitter.com/Joseliyo_Jstnk/status/1620131033474822144
Author: Joseliyo Sanchez, @Joseliyo_Jstnk
Date: 2023-01-18
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection_img:
    Image|endswith:
      -'/iptables'
      -'/xtables-legacy-multi'
      -'/iptables-legacy-multi'
      -'/ip6tables'
      -'/ip6tables-legacy-multi'

  selection_params:
    CommandLine|contains:
      -'-F'
      -'-Z'
      -'-X'

  selection_ufw:
    CommandLine|contains:
      -'ufw-logging-deny'
      -'ufw-logging-allow'
      -'ufw6-logging-deny'
      -'ufw6-logging-allow'

  condition:all of selection_*
Falsepositives:
  -Network administrators
Level: medium