Compliance Node Overview
MITRE ATT&CK T1562.004 (Disable or Modify System Firewall) is an Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage. Changes could be disabling the entire mechanism as well as adding, deleting, or modifying particular rules. This can be done numerous ways depending on the operating system, including via command-line, editing Windows Registry keys, and Windows Control Panel. Affected platforms: Linux, macOS, Windows, Network. MITRE-documented mitigations include M1047 Audit, M1018 User Account Management, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/versions/v16/techniques/T1562/004/
SHA-256 integrity: 2ce04f97310afd44fba2149453a73a66ab24df26ba511b9848292e86f10a018a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1562.004: Disable or Modify System Firewall (https://attack.mitre.org/versions/v16/techniques/T1562/004/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access