1200KM / simulation
T1686 Disable or Modify System Firewall — Attack Simulation
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules…
Technique description
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Stop/Start Packet Filter
Procedure 0ca82ed1-0a94-4774-9a9a-a2c83a8022b7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Opening ports for proxy - HARDRAIN
Procedure 15e57006-79dd-46df-9bf9-31bc24fb5a80; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Tail the UFW firewall log file
Procedure 419cca0c-fa52-4572-b0d7-bc7c6f388a27; elevation required; cleanup not declared. Not executed or individually validated.
- Allow Executable Through Firewall Located in Non-Standard Location
Procedure 6f5822d2-d38d-4f48-9bfc-916607ff6b8c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable iptables
Procedure 7784c64e-ed0b-4b65-bf63-c86db229fd56; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Edit UFW firewall main configuration file
Procedure 7b697ece-8270-46b5-bbc7-6b9e27081831; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LockBit Black - Unusual Windows firewall registry modification -Powershell
Procedure 80b453d1-eec5-4144-bf08-613a6c3ffe12; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Microsoft Defender Firewall
Procedure 88d05800-a5e4-407e-9b53-ece4174f197f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Modify/delete iptables firewall rules
Procedure 899a7fb5-d197-4951-8614-f19ac4a73ad4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Turn off UFW logging
Procedure 8a95b832-2c2a-494d-9cb0-dc9dd97c8bad; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add and delete Packet Filter rules
Procedure 8b23cae1-66c1-41c5-b79d-e095b6098b5b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Blackbit - Disable Windows Firewall using netsh firewall
Procedure 91f348e6-3760-4997-a93b-2ceee7f254ee; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Set a firewall rule using New-NetFirewallRule
Procedure 94be7646-25f6-467e-af23-585fb13000c8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Open a local port through Windows Firewall to any profile
Procedure 9636dd6e-7599-40d2-8eee-ac16434f35ed; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Stop/Start UFW firewall systemctl
Procedure 9fd99609-1854-4f3c-b47b-97d9a5972bd1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LockBit Black - Unusual Windows firewall registry modification -cmd
Procedure a4651931-ebbb-4cde-9363-ddf3d66214cb; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- ESXi - Set Firewall to PASS Traffic
Procedure a67e8aea-ea7c-4c3b-9b1b-8c2957c3091d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Microsoft Defender Firewall via Registry
Procedure afedc8c4-038c-4d82-b3e5-623a95f8a612; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Add and delete UFW firewall rules
Procedure b2563a4e-c4b8-429c-8d47-d5bcb227ba7a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- ESXi - Disable Firewall via Esxcli
Procedure bac8a340-be64-4491-a0cc-0985cb227f5a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Edit UFW firewall user.rules file
Procedure beaf815a-c883-4194-97e9-fdbbb2bbdd7c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Edit UFW firewall ufw.conf file
Procedure c1d8c4eb-88da-4927-ae97-c7c25893803b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Edit UFW firewall sysctl.conf file
Procedure c4ae0701-88d3-4cd8-8bce-4801ed9f97e4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Allow SMB and RDP on Microsoft Defender Firewall
Procedure d9841bf8-f161-4c73-81e9-fd773a5ff8c1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Stop/Start UFW firewall
Procedure fe135572-edcd-49a2-afe6-1d39521c5a9a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.