Disable or Modify System Firewall: Cloud Firewall T1686.001
Tactic: Defense Impairment
Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 66 rules share fields, values, and exclusions.
Fields filtered most (55 distinct)
These fields appear most often in rule filters.
Top indicator values (184 distinct)
These values appear most often in rule predicates.
Exclusions (9 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 19 rules
- Attack protection features manipulation - some attack protection features have been disabled.
- Azure Firewall Modified or Deleted
- Azure Firewall Rule Collection Modified or Deleted
- Azure Network Firewall Policy Modified or Deleted
- Bot detection - the feature is turned off completely or some policies.
- Breached Password Detection - critical settings manipulated
- Brute Force Protection - critical settings manipulated
- Excessive or unexpected Management API scope grants on applications
- Insecure OAuth2.x flows have been enabled for some applications
- Loaded LiquidJS error page template contains XSS vulnerabilities
- MFA downgrade - adaptive MFA risk assessment disabled
- MFA downgrade - disable MFA policies by modifying the policies
- MFA downgrade - disable strong factors
- New Network ACL Entry Added
- New Network Route Added
- Risk for misconfiguration - use of Auth0 tenant name URL.
- Suspicious IP Throttling - critical settings manipulated
- Unauthorized or Unexpected Enabling of Cross-Origin Authentication (CORS)
- Unrecognized IP in attack protection allowlists
Elastic 25 rules
- Attempt to Deactivate an Okta Network Zone
- Attempt to Deactivate an Okta Policy
- Attempt to Deactivate an Okta Policy Rule
- Attempt to Delete an Okta Network Zone
- Attempt to Delete an Okta Policy
- Attempt to Delete an Okta Policy Rule
- Attempt to Modify an Okta Network Zone
- Attempt to Modify an Okta Policy
- Attempt to Modify an Okta Policy Rule
- AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity
- AWS EC2 Network Access Control List Creation
- AWS EC2 Network Access Control List Deletion
- AWS EC2 Security Group Configuration Change
- AWS WAF Access Control List Deletion
- AWS WAF Rule or Rule Group Deletion
- Azure VNet Firewall Front Door WAF Policy Deleted
- Azure VNet Firewall Policy Deleted
- Domain Added to Google Workspace Trusted Domains
- GCP Firewall Rule Creation
- GCP Firewall Rule Deletion
- GCP Firewall Rule Modification
- GCP Virtual Private Cloud Network Deletion
- GCP Virtual Private Cloud Route Creation
- GCP Virtual Private Cloud Route Deletion
- Insecure AWS EC2 VPC Security Group Ingress Rule Added
Splunk 7 rules
- Allow File And Printing Sharing In Firewall
- Allow Network Discovery In Firewall
- ASL AWS Network Access Control List Created with All Open Ports
- ASL AWS Network Access Control List Deleted
- AWS Network Access Control List Created with All Open Ports
- AWS Network Access Control List Deleted
- O365 Bypass MFA via Trusted IP
Kusto 10 rules
- AWSCloudTrail - Changes to Amazon VPC settings
- AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups
- AWSCloudTrail - Changes to AWS Security Group ingress and egress settings
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances
- AWSCloudTrail - Network ACL with all the open ports to a specified CIDR
- Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed)
- Conditional Access - A Conditional Access policy was deleted
- Conditional Access - A Conditional Access policy was disabled
- Conditional Access - A Conditional Access policy was put into report-only mode
- Conditional Access - A new Conditional Access policy was created