Sigma Rule Library

MITRE ATT&CK technique

Disable or Modify System Firewall detection rulesT1686

Disable or Modify System Firewall (T1686) is a MITRE ATT&CK technique in the Defense Impairment tactic. This page lists the 34 community-maintained Sigma detection rules in the library mapped to T1686 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, azure.

Top products

Tactic