Analytics BIOC
Informational
✕
Iptables configuration command was executed
The iptables process was executed with a command to add or delete rules on the host.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify System Firewall (T1562.004)
Attacker's goals:
Adding or deleting system firewalls rules to avoid possible detection.
Investigative actions:
Verify that this isn't IT activity. Look for other hosts executing similar commands.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
7 variations:
- Rare iptables port forward command was executed Low (parent: Informational)
- Uncommon iptables port forward command was executed on the host Informational
- Rare iptables delete command was executed Low (parent: Informational)
- A rare iptables delete command was executed on the host Informational
- A rare iptables flush all command was executed Low (parent: Informational)
- A rare iptables flush command was executed Low (parent: Informational)
- A rare iptables flush command was executed on the host Informational