Linux process commands stopping firewall and security services
Flags Linux commands that stop/disable firewall/security services or set SELinux enforcement to 0.
- Product
- linux
- Category
- process_creation
- Author
- Ömer Günal, Alejandro Ortuno, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-06-17
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Linux process activity where commands attempt to stop or disable common security controls, including iptables/ip6tables, firewalld, and endpoint protection services (e.g., cbdaemon and falcon-sensor). Such actions can impair host defenses and are consistent with attacker attempts to evade detection or maintain persistence. It relies on process creation telemetry, matching image paths and command-line arguments like stop/disable/off and service identifiers.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux process commands stopping firewall and security services
id: 6c166716-026e-4be7-9515-5643f4d79a03
status: test
description: This rule identifies Linux process activity where commands attempt to stop or disable common security controls, including iptables/ip6tables, firewalld, and endpoint protection services (e.g., cbdaemon and falcon-sensor). Such actions can impair host defenses and are consistent with attacker attempts to evade detection or maintain persistence. It relies on process creation telemetry, matching image paths and command-line arguments like stop/disable/off and service identifiers.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.004/T1562.004.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_security_tools_disabling.yml
author: Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule Team
date: 2020-06-17
modified: 2022-10-09
tags:
- attack.defense-impairment
- attack.t1686
logsource:
category: process_creation
product: linux
detection:
selection_iptables_1:
Image|endswith: /service
CommandLine|contains|all:
- iptables
- stop
selection_iptables_2:
Image|endswith: /service
CommandLine|contains|all:
- ip6tables
- stop
selection_iptables_3:
Image|endswith: /chkconfig
CommandLine|contains|all:
- iptables
- stop
selection_iptables_4:
Image|endswith: /chkconfig
CommandLine|contains|all:
- ip6tables
- stop
selection_firewall_1:
Image|endswith: /systemctl
CommandLine|contains|all:
- firewalld
- stop
selection_firewall_2:
Image|endswith: /systemctl
CommandLine|contains|all:
- firewalld
- disable
selection_carbonblack_1:
Image|endswith: /service
CommandLine|contains|all:
- cbdaemon
- stop
selection_carbonblack_2:
Image|endswith: /chkconfig
CommandLine|contains|all:
- cbdaemon
- off
selection_carbonblack_3:
Image|endswith: /systemctl
CommandLine|contains|all:
- cbdaemon
- stop
selection_carbonblack_4:
Image|endswith: /systemctl
CommandLine|contains|all:
- cbdaemon
- disable
selection_selinux:
Image|endswith: /setenforce
CommandLine|contains: "0"
selection_crowdstrike_1:
Image|endswith: /systemctl
CommandLine|contains|all:
- stop
- falcon-sensor
selection_crowdstrike_2:
Image|endswith: /systemctl
CommandLine|contains|all:
- disable
- falcon-sensor
condition: 1 of selection*
falsepositives:
- Legitimate administration activities
level: medium
license: DRL-1.1
related:
- id: e3a8a052-111f-4606-9aee-f28ebeb76776
type: derived