<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>attack.t1686.001 on Detection.FYI</title>
    <link>https://detection.fyi/tags/attack.t1686.001/</link>
    <description>Recent content in attack.t1686.001 on Detection.FYI</description>
    <generator>Hugo -- gohugo.io</generator>
    <copyright> </copyright>
    <lastBuildDate>Tue, 28 Apr 2026 23:20:23 +0000</lastBuildDate><atom:link href="https://detection.fyi/tags/attack.t1686.001/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Azure Firewall Modified or Deleted</title>
      <link>https://detection.fyi/sigmahq/sigma/cloud/azure/activity_logs/azure_firewall_modified_or_deleted/</link>
      <pubDate>Tue, 28 Apr 2026 23:20:23 +0000</pubDate>
      
      <guid>https://detection.fyi/sigmahq/sigma/cloud/azure/activity_logs/azure_firewall_modified_or_deleted/</guid>
      <description>
        
          
            Identifies when a firewall is created, modified, or deleted.
          
          
        
      </description>
    </item>
    
    <item>
      <title>Azure Firewall Rule Collection Modified or Deleted</title>
      <link>https://detection.fyi/sigmahq/sigma/cloud/azure/activity_logs/azure_firewall_rule_collection_modified_or_deleted/</link>
      <pubDate>Tue, 28 Apr 2026 23:20:23 +0000</pubDate>
      
      <guid>https://detection.fyi/sigmahq/sigma/cloud/azure/activity_logs/azure_firewall_rule_collection_modified_or_deleted/</guid>
      <description>
        
          
            Identifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.
          
          
        
      </description>
    </item>
    
    <item>
      <title>Azure Network Firewall Policy Modified or Deleted</title>
      <link>https://detection.fyi/sigmahq/sigma/cloud/azure/activity_logs/azure_network_firewall_policy_modified_or_deleted/</link>
      <pubDate>Tue, 28 Apr 2026 23:20:23 +0000</pubDate>
      
      <guid>https://detection.fyi/sigmahq/sigma/cloud/azure/activity_logs/azure_network_firewall_policy_modified_or_deleted/</guid>
      <description>
        
          
            Identifies when a Firewall Policy is Modified or Deleted.
          
          
        
      </description>
    </item>
    
    <item>
      <title>New Network ACL Entry Added</title>
      <link>https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_new_acl_entries/</link>
      <pubDate>Tue, 28 Apr 2026 23:20:23 +0000</pubDate>
      
      <guid>https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_new_acl_entries/</guid>
      <description>
        
          
            Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.

          
          
        
      </description>
    </item>
    
    <item>
      <title>New Network Route Added</title>
      <link>https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_new_route_added/</link>
      <pubDate>Tue, 28 Apr 2026 23:20:23 +0000</pubDate>
      
      <guid>https://detection.fyi/sigmahq/sigma/cloud/aws/cloudtrail/aws_cloudtrail_new_route_added/</guid>
      <description>
        
          
            Detects the addition of a new network route to a route table in AWS.

          
          
        
      </description>
    </item>
    
  </channel>
</rss>
