1200KM / detection
T1686.001 Cloud Firewall — Detection Rules
Detection workspace for T1686.001 Cloud Firewall: 5 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- New Network ACL Entry Added · test · low · {"product":"aws","service":"cloudtrail"}
- New Network Route Added · test · medium · {"product":"aws","service":"cloudtrail"}
- Azure Firewall Modified or Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Firewall Rule Collection Modified or Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Network Firewall Policy Modified or Deleted · test · medium · {"product":"azure","service":"activitylogs"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0424 Detection Strategy for Disable or Modify Cloud Firewall
AN1188 Analytic 1188
Creation, deletion, or modification of security groups and firewall rules in cloud control plane logs that expand access to cloud resources beyond expected baselines. Defender view: unexpected ingress/egress rules permitting 0.0.0.0/0 or opening atypical ports, often correlated with privileged role or API key activity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.