T1686.002sub-technique of T1686 Disable or Modify System Firewall

Network Device Firewall

Network Devicesnothing on this site yetT1686.002 on attack.mitre.org

Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage. Adversaries may obtain access to devices such as routers, switches, or other perimeter/network devices and change access control lists (ACLs), security zones, or policy rules to permit otherwise blocked traffic.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

how MITRE says to see it

Detection of Unauthorized Network Firewall Rule Modification

  • Defender observes configuration changes on firewall/network appliance involving rule creation, modification, or deletion from abnormal management IPs or non-console channels (e.g., remote CLI, API).

what reduces it

  • M1018 User Account Management. Ensure proper user permissions are in place to prevent adversaries from disabling or modifying firewall settings.
  • M1047 Audit. Routinely check account role permissions to ensure only expected users and roles have permission to modify system firewalls.
  • M1051 Update Software. Ensure the network firewall is up to date with security patches.

the rest of T1686

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.