Cross-source coverage

T1562.007 / ATT&CK

Impair Defenses: Disable or Modify Cloud Firewall

ATT&CK has retired this technique. Rules still tag it; the current id is T1686.001 Disable or Modify System Firewall: Cloud Firewall.

35 rules across 4 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud firewalls are separate from system firewalls that are described in Disable or Modify System Firewall.

Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary with appropriate permissions may introduce new firewall rules or policies to allow access into a victim cloud environment and/or move laterally from the cloud control plane to the data plane. For example, an adversary may use a script or utility that creates new ingress rules in existing security groups (or creates new security groups entirely) to allow any TCP/IP connectivity to a cloud-hosted instance. They may also remove networking limitations to support traffic associated with malicious activity (such as cryptomining).

Modifying or disabling a cloud firewall may enable adversary C2 communications, lateral movement, and/or data exfiltration that would otherwise not be allowed. It may also be used to open up resources for Brute Force or Endpoint Denial of Service.

Tactics
Stealth
Platforms
IaaS
Telemetry

elastic/detection-rules

27 rules
Detection Severity Format
Domain Added to Google Workspace Trusted Domains High Elastic TOML
Attempt to Deactivate an Okta Network Zone Medium Elastic TOML
Attempt to Deactivate an Okta Policy Rule Medium Elastic TOML
Attempt to Delete an Okta Network Zone Medium Elastic TOML
Attempt to Delete an Okta Policy Medium Elastic TOML
Attempt to Modify an Okta Network Zone Medium Elastic TOML
AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity Medium Elastic TOML
AWS EC2 Network Access Control List Deletion Medium Elastic TOML
AWS WAF Access Control List Deletion Medium Elastic TOML
AWS WAF Rule or Rule Group Deletion Medium Elastic TOML

+ 17 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

4 rules
Detection Severity Format
AWS RDS Instance Modified to be Publicly Accessible Critical Panther Python
AWS RDS Security Group Ingress Authorized Medium Panther Python
Azure Network Security Configuration Modified or Deleted Medium Panther Python
OpenAI IP Allowlist Configuration Changes Medium Panther Python

Wazuh Core Ruleset

3 rules
Detection Severity Format
Security group with inbound rules allowing "Unknown cidrIp" on port "Unknown port" detected. High Wazuh XML
GCP firewall rule deleted. Low Wazuh XML
GCP firewall rule modified. Low Wazuh XML

chronicle/detection-rules

1 rule
Detection Severity Format
google_workspace_new_trusted_domain_added High YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.