kevmap

TechniquesT1686 › T1686.003

T1686.003 Windows Host Firewall

defense impairment — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
20
Sigma rules tagged attack.t1686.003
0
KEV CVEs mapped here
<p>Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage. This can include disabling the Windows host firewall entirely, suppressing specific profiles (domain, private, public), or adding, deleting, and modifying firewall rules to allow or restrict traffic.</p><p>Adversaries may perform these modifications through multiple mechanisms depending on the Windows operating system and access level. For example, adversaries may use command-line utilities (e.g., netsh advfirewall or PowerShell cmdlets like Set-NetFirewallProfile, New-NetFirewallRule), Windows Registry modifications (e.g., altering firewall states and rule configurations via registry keys), or the Windows Control Panel to modify firewall settings through the Windows Security interface.</p><p>By disabling or modifying Windows firewall services, adversaries may enable access to remote services, open ports for command and control traffic, or configure rules for further actions.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1686.003

Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2022-02-19 (modified 2023-04-21) · logsource: product=windows service=firewall-as · 00bb5bd5-1379-4fcf-a965-a5b6f7478064
Detects activity when the settings of the Windows firewall have been changed
Techniques: T1686.003
Author: Sander Wiebing · 2020-05-23 (modified 2023-12-11) · logsource: product=windows category=process_creation · 01aeb693-138d-49d2-9403-c4f52d7d3d62
Detects usage of the netsh command to open and allow connections to port 3389 (RDP). As seen used by Sarwent Malware
Techniques: T1686.003
Author: frack113 · 2022-02-19 (modified 2023-04-21) · logsource: product=windows service=firewall-as · 04b60639-39c0-412a-9fbe-e82499c881a3
Detects activity when Windows Defender Firewall has been reset to its default configuration
Techniques: T1686.003
Author: frack113 · 2022-08-14 (modified 2025-10-07) · logsource: product=windows category=process_creation · 1a5fefe6-734f-452e-a07d-fc1c35bce4b2
Detects the removal of a port or application rule in the Windows Firewall configuration using netsh
Techniques: T1686.003
Author: frack113 · 2022-01-09 (modified 2023-02-14) · logsource: product=windows category=process_creation · 347906f3-e207-4d18-ae5b-a9403d6bcdef
Adversaries may modify system firewalls in order to bypass controls limiting network usage
Techniques: T1686.003
Author: Austin Songer @austinsonger · 2021-10-12 (modified 2022-12-30) · logsource: product=windows category=ps_script · 488b44e7-3781-4a71-888d-c95abfacf44d
Detects when a user disables the Windows Firewall via a Profile to help evade defense.
Techniques: T1686.003
Author: frack113 · 2024-05-03 · logsource: product=windows category=process_creation · 51483085-0cba-46a8-837e-4416496d6971
Detects calls to the "New-NetFirewallRule" cmdlet from PowerShell in order to add a new firewall rule with an "Allow" action.
Techniques: T1686.003
Author: frack113 · 2022-02-19 (modified 2024-01-22) · logsource: product=windows service=firewall-as · 5570c4d9-8fdd-4622-965b-403a5a101aa0
Detects when a rule has been modified in the Windows firewall exception list
Techniques: T1686.003
Author: Fatih Sirin · 2019-11-01 (modified 2023-02-13) · logsource: product=windows category=process_creation · 57c4bf16-227f-4394-8ec7-1b745ee061c3
Detects netsh commands that turns off the Windows firewall
Techniques: T1686.003
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2023-01-17 (modified 2024-01-22) · logsource: product=windows service=firewall-as · 79609c82-a488-426e-abcf-9f341a39365d
Detects when a all the rules have been deleted from the Windows Defender Firewall configuration
Techniques: T1686.003
Author: frack113 · 2022-02-19 (modified 2023-01-17) · logsource: product=windows service=firewall-as · 7ec15688-fd24-4177-ba43-1a950537ee39
Detects activity when The Windows Defender Firewall service failed to load Group Policy
Techniques: T1686.003
Author: frack113 · 2024-05-10 · logsource: product=windows category=ps_script · 8d31dd2e-b582-48ca-826e-dcaa2c1ca264
Detects when a powershell script contains calls to the "New-NetFirewallRule" cmdlet in order to add a new firewall rule with an "Allow" action.
Techniques: T1686.003
Author: frack113 · 2022-01-09 (modified 2024-03-25) · logsource: product=windows category=registry_set · 974515da-6cc5-4c95-ae65-f97f9150ec7f
Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage
Techniques: T1686.003
Author: frack113 · 2023-02-26 (modified 2024-05-10) · logsource: product=windows service=firewall-as · 9e2575e7-2cb9-4da1-adc8-ed94221dca5e
Detects the addition of a new rule to the Windows Firewall exception list for an application located in a potentially suspicious location.
Techniques: T1686.003
Author: Sander Wiebing, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community · 2020-05-25 (modified 2023-12-11) · logsource: product=windows category=process_creation · a35f5a72-f347-4e36-8895-9869b0d5fc6d
Detects Netsh command execution that whitelists a program located in a suspicious location in the Windows Firewall
Techniques: T1686.003
Author: frack113 · 2022-02-19 (modified 2024-08-29) · logsource: product=windows service=firewall-as · c187c075-bb3e-4c62-b4fa-beae0ffc211f
Detects when a single rules or all of the rules have been deleted from the Windows Defender Firewall
Techniques: T1686.003
Author: Markus Neis, Sander Wiebing · 2019-01-29 (modified 2023-02-10) · logsource: product=windows category=process_creation · cd5cfd80-aa5f-44c0-9c20-108c4ae12e3c
Detects the addition of a new rule to the Windows firewall via netsh
Techniques: T1686.003
Author: frack113 · 2022-02-19 (modified 2026-08-06) · logsource: product=windows service=firewall-as · cde0a575-7d3d-4a49-9817-b8004a7bf105
Detects when a rule has been added to the Windows Firewall exception list
Techniques: T1686.003
Author: frack113 · 2022-08-19 (modified 2023-08-17) · logsource: product=windows category=registry_set · e78c408a-e2ea-43cd-b5ea-51975cf358c0
Detect set EnableFirewall to 0 to disable the Windows firewall
Techniques: T1686.003
Author: frack113, Nasreddine Bencherchali (Nextron Systems) · 2024-05-10 · logsource: product=windows service=firewall-as · eca81e8d-09e1-4d04-8614-c91f44fd0519
Detects the addition of a new "Allow" firewall rule by the WMI process (WmiPrvSE.EXE). This can occur if an attacker leverages PowerShell cmdlets such as "New-NetFirewallRule", or directly uses WMI CIM classes such as "MSFT_NetFirewallRule".
Techniques: T1686.003

Rules tagged at the parent level (attack.t1686) 7

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: IAI · 2023-03-06 (modified 2025-10-12) · logsource: product=linux service=auditd · 323ff3f5-0013-4847-bbd4-250b5edb62cc
Detects the removal of system firewall rules. Adversaries may only delete or modify a specific system firewall rule to bypass controls limiting network usage or access. Detection rules that match only on the disabling of firewalls will miss this.
Techniques: T1686
Author: Joseliyo Sanchez, @Joseliyo_Jstnk · 2023-01-18 · logsource: product=linux category=process_creation · 3be619f4-d9ec-4ea8-a173-18fdd01996ab
Detect use of iptables to flush all firewall rules, tables and chains and allow all network traffic
Techniques: T1686
Author: Ömer Günal, Alejandro Ortuno, oscd.community · 2020-06-17 (modified 2022-11-26) · logsource: product=linux service=syslog · 49f5dfc1-f92e-4d34-96fa-feba3f6acf36
Detects disabling security tools
Techniques: T1686
Author: Pawel Mazur · 2022-01-22 · logsource: product=linux service=auditd · 53059bc0-1472-438b-956a-7508a94a91f0
Detects disabling of system firewalls which could be used by adversaries to bypass controls that limit usage of the network.
Techniques: T1686
Author: Rafal Piasecki · 2022-08-10 · logsource: product=linux service=auditd · 70b4156e-50fc-4523-aa50-c9dddf1993fc
All TCP traffic on particular port from attacker is routed to different port. ex. '/sbin/iptables -t nat -D PREROUTING -p tcp -s 192.168.1.1 --dport 22 -j REDIRECT --to-ports 42392' The traffic looks like encrypted SSH communications going to TCP port 22, but in reality is being directed to the shell port once it hits the iptables rule for the attacker host only.
Techniques: T1686
Author: Joseliyo Sanchez, @Joseliyo_Jstnk · 2023-01-18 (modified 2026-05-04) · logsource: product=linux category=process_creation · 84c9e83c-599a-458a-a0cb-0ecce44e807a
Detects attempts to disable the Uncomplicated Firewall (UFW) on Linux systems. UFW is a popular firewall management tool that provides an easy-to-use interface for configuring firewall rules. Disabling UFW can leave a system vulnerable to attacks, as it may allow unauthorized access to network services and resources.
Techniques: T1686
Author: Ömer Günal, Alejandro Ortuno, oscd.community · 2020-06-17 (modified 2022-10-09) · logsource: product=linux category=process_creation · e3a8a052-111f-4606-9aee-f28ebeb76776
Detects disabling security tools
Techniques: T1686