Log sources › networkdevice:Firewall
networkdevice:Firewall
Inverted view: what can be detected if this is the log you have. Network Devices
3
channels
1
analytics
1
techniques
0
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Audit trail or CLI/API access indicating commands like no access-list, delete rule-set, clear config |
DC0064 Command Execution | AN0855 | 1 |
Login from untrusted IP, or new admin account accessing firewall console/API |
DC0067 Logon Session Creation | AN0855 | 1 |
update_rule: Access control or NAT rule modified or disabled outside maintenance window |
DC0051 Firewall Rule Modification | AN0855 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1686.002 Network Device Firewall | defense impairment | 2 | 0 |