Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0306 — Detection of Unauthorized Network Firewall Rule Modification
DET0306

Detection of Unauthorized Network Firewall Rule Modification

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0855 Analytic 0855
Network Devices

Defender observes configuration changes on firewall/network appliance involving rule creation, modification, or deletion from abnormal management IPs or non-console channels (e.g., remote CLI, API). These are often correlated with a spike in previously blocked outbound traffic, unexpected allow-all rules, or bulk rule deletions. Behavior often follows unauthorized login, privilege escalation, or API abuse.

networkdevice:Firewall update_rule: Access control or NAT rule modified or disabled outside maintenance window networkdevice:Firewall Login from untrusted IP, or new admin account accessing firewall console/API networkdevice:Firewall Audit trail or CLI/API access indicating commands like no access-list, delete rule-set, clear config NSM:Flow Outbound traffic spike through formerly blocked ports/subnets following config change
[TrustedAdminIPs] Allowlisted IPs/subnets where administrative access is expected (e.g., jump box, VPN mgmt)
[ConfigChangeWindow] Expected maintenance window (e.g., 02:00–04:00 UTC) to filter benign changes
[RuleScopeThreshold] Number of rules affected or port ranges modified to determine severity
[NewUserPrivilegeThreshold] Flag new users making changes without observed privilege elevation path

Detected Techniques

1

Details

MITRE ID
DET0306
STIX ID
x-mitre-detection-strategy--3a114d11-0850-4c33-b828-359e59b15250
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.