Compliance Node Overview
MITRE ATT&CK T1686.003 (Windows Host Firewall) is an Enterprise Defense Impairment technique. Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage. This can include disabling the Windows host firewall entirely, suppressing specific profiles (domain, private, public), or adding, deleting, and modifying firewall rules to allow or restrict traffic. Adversaries may perform these modifications through multiple mechanisms depending on the Windows operating system and access level. For example, adversaries may use command-line utilities (e.g., `netsh advfirewall` or PowerShell cmdlets like `Set-NetFirewallProfile`, `New-NetFirewallRule`), Windows Registry modifications (e.g., altering firewall states and rule configurations via registry keys), or the Windows Control Panel to modify firewall settings through the Windows Security interface. B... Affected platforms: Windows. Sub-technique of ATT&CK T1686. ATT&CK-mapped mitigations: M1022 Restrict File and Directory Permissions, M1024 Restrict Registry Permissions, M1018 User Account Management, M1047 Audit.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1686/003/
SHA-256 integrity: b48b4785f28ddcf7da0e16ff0f8542c71c60e49fcee3bcb3733653bca40ee9ae
Primary Citations — 8 traced to source
- MITRE ATT&CK Technique T1686.003: Windows Host Firewall (https://attack.mitre.org/techniques/T1686/003/)
- MITRE ATT&CK Tactic TA0112: Defense Impairment (https://attack.mitre.org/tactics/TA0112/)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access