Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0112 ✕ technique: T1686 ✕
Download CSV Show ATT&CK heatmapIptables configuration command was executed Informational 7 variations
The iptables process was executed with a command to add or delete rules on the host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Impairment (TA0112)ATT&CK techniques: Disable or Modify System Firewall (T1686)Required data: XDR AgentAttacker's goals: Adding or deleting system firewalls rules to avoid possible detection.Investigative actions: Verify that this isn't IT activity. Look for other hosts executing similar commands.Variations
Rare iptables port forward command was executed
Low overridden
An iptables command was executed to perform port forward, This command is unpopular. overridden
Uncommon iptables port forward command was executed on the host
Informational overridden
An iptables command was executed to perform port forward, This command is uncommon for the host. overridden
Rare iptables delete command was executed
Low overridden
An iptables command was executed to delete rule, This command is unpopular. overridden
A rare iptables delete command was executed on the host
Informational overridden
An iptables command was executed to delete rule, This command is uncommon for the host. overridden
A rare iptables flush all command was executed
Low overridden
An iptables command was executed to flush all rules, This command is unpopular. overridden
A rare iptables flush command was executed
Low overridden
An iptables command was executed to flush all rules, This command is unpopular. overridden
A rare iptables flush command was executed on the host
Informational overridden
An iptables command was executed to flush rules, This command is uncommon for the host. overridden