{"id":"T1686.002","name":"Network Device Firewall","url":"https://attack.mitre.org/techniques/T1686/002","tactics":["defense-impairment"],"platforms":["Network Devices"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0306","stix_id":"x-mitre-detection-strategy--3a114d11-0850-4c33-b828-359e59b15250","name":"Detection of Unauthorized Network Firewall Rule Modification","url":"https://attack.mitre.org/detectionstrategies/DET0306","analytics":[{"id":"AN0855","stix_id":"x-mitre-analytic--17ce541a-23fa-4b33-affc-c6ba906e9956","name":"Analytic 0855","description":"Defender observes configuration changes on firewall/network appliance involving rule creation, modification, or deletion from abnormal management IPs or non-console channels (e.g., remote CLI, API). These are often correlated with a spike in previously blocked outbound traffic, unexpected allow-all rules, or bulk rule deletions. Behavior often follows unauthorized login, privilege escalation, or API abuse.","url":"https://attack.mitre.org/detectionstrategies/DET0306#AN0855","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:Firewall","channel":"update_rule: Access control or NAT rule modified or disabled outside maintenance window","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"networkdevice-firewall"},{"name":"networkdevice:Firewall","channel":"Login from untrusted IP, or new admin account accessing firewall console/API","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"networkdevice-firewall"},{"name":"networkdevice:Firewall","channel":"Audit trail or CLI/API access indicating commands like no access-list, delete rule-set, clear config","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-firewall"},{"name":"NSM:Flow","channel":"Outbound traffic spike through formerly blocked ports/subnets following config change","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TrustedAdminIPs","description":"Allowlisted IPs/subnets where administrative access is expected (e.g., jump box, VPN mgmt)"},{"field":"ConfigChangeWindow","description":"Expected maintenance window (e.g., 02:00–04:00 UTC) to filter benign changes"},{"field":"RuleScopeThreshold","description":"Number of rules affected or port ranges modified to determine severity"},{"field":"NewUserPrivilegeThreshold","description":"Flag new users making changes without observed privilege elevation path"}],"live":true,"detection_strategies":["DET0306"],"techniques":["T1686.002"]}],"live":true,"version":"1.0","techniques":["T1686.002"]}],"sigma_rules":[{"id":"5c8d7b41-3812-432f-a0bb-4cfb7c31827e","title":"FortiGate - Firewall Address Object Added","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2025-11-01","modified":"2026-05-04","description":"Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.","references":["https://www.fortiguard.com/psirt/FG-IR-24-535","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event","https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/306021697/config-firewall-address","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr"],"logsource":{"product":"fortigate","service":"event"},"tags":["attack.defense-impairment","attack.t1686.002"],"path":"rules/network/fortinet/fortigate/fortinet_fortigate_new_firewall_address_object.yml","techniques":["T1686.002"],"cves":[]},{"id":"f24ab7a8-f09a-4319-82c1-915586aa642b","title":"FortiGate - New Firewall Policy Added","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2025-11-01","modified":"2026-05-04","description":"Detects the addition of a new firewall policy on a Fortinet FortiGate Firewall.","references":["https://www.fortiguard.com/psirt/FG-IR-24-535","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event","https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/333889629/config-firewall-policy","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr"],"logsource":{"product":"fortigate","service":"event"},"tags":["attack.defense-impairment","attack.t1686.002"],"path":"rules/network/fortinet/fortigate/fortinet_fortigate_new_firewall_policy_added.yml","techniques":["T1686.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}