1200KM / detection
T1686 Disable or Modify System Firewall — Detection Rules
Detection workspace for T1686 Disable or Modify System Firewall: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bpfdoor TCP Ports Redirect · test · medium · {"product":"linux","service":"auditd"}
- Modify System Firewall · test · medium · {"product":"linux","service":"auditd"}
- Disable System Firewall · test · high · {"product":"linux","service":"auditd"}
- Disabling Security Tools - Builtin · test · medium · {"product":"linux","service":"syslog"}
- UFW Disable Attempt · test · medium · {"product":"linux","category":"process_creation"}
- Flush Iptables Ufw Chain · test · medium · {"product":"linux","category":"process_creation"}
- Disabling Security Tools · test · medium · {"category":"process_creation","product":"linux"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0145 Detection of Disabled or Modified System Firewalls across OS Platforms.
AN0406 Analytic 0406
Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy also indicate adversarial actions.
AN0407 Analytic 0407
Detection of iptables, nftables, or firewalld rule modifications. Correlation of sudden drops in active firewall rules with suspicious processes suggests adversarial evasion.
AN0408 Analytic 0408
Detection of PF firewall rule modifications via pfctl, socketfilterfw, or defaults write to com.apple.alf. Adversaries often disable firewall profiles entirely or whitelist malicious processes.
AN0409 Analytic 0409
Detection of firewall changes using esxcli network firewall set or vSphere API modifications. Sudden disabling of firewall rules across management interfaces is a strong adversarial signal.
AN0410 Analytic 0410
Detection of firewall ACL or rule base changes through CLI (e.g., no access-list, permit any any). Monitor configuration commits from unusual users or sessions.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.