Iptables configuration command was executed
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify System Firewall (T1686)
Severity
Informational
Description
The iptables process was executed with a command to add or delete rules on the host.
Attacker's Goals
Adding or deleting system firewalls rules to avoid possible detection.
Investigative actions
Verify that this isn't IT activity.
Look for other hosts executing similar commands.
Variations
Was this helpful?
