T1686.002sub-technique of T1686 Disable or Modify System Firewall
Network Device Firewall
Network Devicesnothing on this site yetT1686.002 on attack.mitre.org
Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage. Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Ransomware, suspected or confirmed
Files renamed or unreadable, a ransom note, or backup deletion commands seen.
how MITRE says to see it
Detection of Unauthorized Network Firewall Rule Modification
- Defender observes configuration changes on firewall/network appliance involving rule creation, modification, or deletion from abnormal management IPs or non-console channels (e.g., remote CLI, API).
what reduces it
- M1018 User Account Management. Ensure proper user permissions are in place to prevent adversaries from disabling or modifying firewall settings.
- M1047 Audit. Routinely check account role permissions to ensure only expected users and roles have permission to modify system firewalls.
- M1051 Update Software. Ensure the network firewall is up to date with security patches.