Cross-source coverage
T1562.007 / ATT&CK
Impair Defenses: Disable or Modify Cloud Firewall
ATT&CK has retired this technique. Rules still tag it; the current id is T1686.001 Disable or Modify System Firewall: Cloud Firewall.
35 rules across 4 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud firewalls are separate from system firewalls that are described in Disable or Modify System Firewall.
Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary with appropriate permissions may introduce new firewall rules or policies to allow access into a victim cloud environment and/or move laterally from the cloud control plane to the data plane. For example, an adversary may use a script or utility that creates new ingress rules in existing security groups (or creates new security groups entirely) to allow any TCP/IP connectivity to a cloud-hosted instance. They may also remove networking limitations to support traffic associated with malicious activity (such as cryptomining).
Modifying or disabling a cloud firewall may enable adversary C2 communications, lateral movement, and/or data exfiltration that would otherwise not be allowed. It may also be used to open up resources for Brute Force or Endpoint Denial of Service.
- Tactics
- Stealth
- Platforms
- IaaS
- Telemetry
- —
elastic/detection-rules
27 rules| Detection | Severity | Format |
|---|---|---|
| Domain Added to Google Workspace Trusted Domains | High | Elastic TOML |
| Attempt to Deactivate an Okta Network Zone | Medium | Elastic TOML |
| Attempt to Deactivate an Okta Policy Rule | Medium | Elastic TOML |
| Attempt to Delete an Okta Network Zone | Medium | Elastic TOML |
| Attempt to Delete an Okta Policy | Medium | Elastic TOML |
| Attempt to Modify an Okta Network Zone | Medium | Elastic TOML |
| AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity | Medium | Elastic TOML |
| AWS EC2 Network Access Control List Deletion | Medium | Elastic TOML |
| AWS WAF Access Control List Deletion | Medium | Elastic TOML |
| AWS WAF Rule or Rule Group Deletion | Medium | Elastic TOML |
+ 17 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
4 rules| Detection | Severity | Format |
|---|---|---|
| AWS RDS Instance Modified to be Publicly Accessible | Critical | Panther Python |
| AWS RDS Security Group Ingress Authorized | Medium | Panther Python |
| Azure Network Security Configuration Modified or Deleted | Medium | Panther Python |
| OpenAI IP Allowlist Configuration Changes | Medium | Panther Python |
Wazuh Core Ruleset
3 rules| Detection | Severity | Format |
|---|---|---|
| Security group with inbound rules allowing "Unknown cidrIp" on port "Unknown port" detected. | High | Wazuh XML |
| GCP firewall rule deleted. | Low | Wazuh XML |
| GCP firewall rule modified. | Low | Wazuh XML |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| google_workspace_new_trusted_domain_added | High | YARA-L |