MITRE ATT&CK Technique
T1686Disable or Modify System Firewall
- First Reported
- Sep 21, 2026
- Latest Reported
- Sep 21, 2026
Official Description
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with firewall services, policies, or rule sets to remove restrictions on inbound or outbound traffic. For example, this may include turning off firewall profiles, altering existing rules to permit previously blocked ports or protocols, or adding new rules that create covert communication paths (e.g., adding a new firewall rule for a well-known protocol (such as RDP) using a non-traditional and potentially less securitized port.(Citation: change_rdp_port_conti)
Adversaries may disable or modify firewalls using different behaviors, depending on the platform. For example, in ESXi, firewall rules may be modified directly via the esxcli (e.g., via esxcli network firewall set) or via the vCenter user interface.(Citation: Broadcom ESXi Firewall)(Citation: Trellix Rnasomhouse 2024)
Adversaries may disable or modify firewalls using different behaviors, depending on the platform. For example, in ESXi, firewall rules may be modified directly via the esxcli (e.g., via esxcli network firewall set) or via the vCenter user interface.(Citation: Broadcom ESXi Firewall)(Citation: Trellix Rnasomhouse 2024)
- Tactics
- Defense Impairment
- Platforms
- ESXi, Linux, macOS, Network Devices, Windows
- MITRE Version
- 1.0
- Last Modified
- May 12, 2026
Sub-techniques (3)
Reported Context (1)
- The article's ATT&CK mapping assigns firewall disablement through the win Firewall Off GPO to this ID. PAYLOAD Ransomware Used Malicious Active Directory Policies to Disrupt a Manufacturing Firm
Malware (1)
MITRE ATT&CK (8)
Vendors (1)
Products (7)
Tools (2)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.