Firewall Rule Deleted Via Netsh.EXE

 Original Source: [Sigma source]
Title: Firewall Rule Deleted Via Netsh.EXE
Status: test
Description:Detects the removal of a port or application rule in the Windows Firewall configuration using netsh
References:
  -https://app.any.run/tasks/8bbd5b4c-b82d-4e6d-a3ea-d454594a37cc/
Author: frack113
Date: 2022-08-14
modified:2025-10-07
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\netsh.exe' OriginalFileName:'netsh.exe'   selection_cli:
    CommandLine|contains|all:
      -'firewall'
      -'delete '

  filter_optional_dropbox:
    ParentImage|endswith: '\Dropbox.exe'
    CommandLine|contains: 'name=Dropbox'
  filter_optional_avast:
    ParentImage|endswith: '\instup.exe'
    CommandLine|contains: 'advfirewall firewall delete rule name="Avast Antivirus Admin Client"'
  condition:all of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Legitimate administration activity
  -Software installations and removal
Level: medium