Linux Auditd: Stop Firewalld, iptables, or UFW Services

Detects stopping firewall services (firewalld/iptables/ufw) on Linux via auditd service-stop events.

FreeReviewedSigma · High · v3
Product
linux
Service
auditd
Author
Pawel Mazur (SigmaHQ), DRL 1.1
Published
2022-01-22
Updated
2026-07-31

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies attempts to disable host firewall enforcement by stopping the firewalld, iptables, or UFW services. Attackers often impair defenses to reduce network filtering and make it easier to reach internal or external targets. It relies on auditd service stop telemetry that records unit stop events for these specific firewall components.

Related detections9 linkedT1686 — drag to rearrange
Suspicious Disabling or Flushing of the Linux Host Firewall (via process_creation)
Malicious Firewall Deactivation - PowerShell (via powershell)
Malicious Firewall Deactivation - Firewall (via firewall-as)
Suspicious Outbound Firewall Block Rule Added via Netsh Advfirewall
Malicious Windows Firewall Disable via Netsh
OpenSSH Server Firewall Configuration on Windows - Firewall (via firewall-as)
Suspicious Firewall Rule Added Using PowerShell or CMD (via firewall-as)
Suspicious Firewall Rule Masquerading as CloudExperienceHost via netsh
Suspicious Firewall Rule Masquerading As Windows Update (via process_creation)
Linux Auditd: Stop Firewalld, iptables, or UFW Services
Pivot detection · T1686 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.