BIOC
Informational
✕
MacOS firewall manipulation
An attacker may modify a firewall via command line to bypass network controls.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses (T1562) Impair Defenses: Disable or Modify System Firewall (T1562.004)
Indicator:
Process action type = execution AND target process name = socketfilterfw , launchctl , kextunload AND target process cmd = *unblockapp* , *--setglobalstate off* , *unload*com.apple.alf.useragent.plist* , *com.apple.nke.applicationfirewall* Host host os = macos
Preventable: yes