// MITRE ATT&CK

T1686.001 · Cloud Firewall

🎯 Defense Impairment IaaS Sub-technique

Sub-technique of T1686 · Disable or Modify System Firewall.

Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and prot...

How to detect & mitigate it

Detecting Cloud Firewall starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.