Title:
Firewall Rule Deleted Via Netsh.EXE
Status:
test
Description:Detects the removal of a port or application rule in the Windows Firewall configuration using netsh
References:
-https://app.any.run/tasks/8bbd5b4c-b82d-4e6d-a3ea-d454594a37cc/
Author: frack113
Date: 2022-08-14
modified:2025-10-07
Tags:
- -'attack.defense-impairment'
- -'attack.t1686.003'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
Image|endswith:
'\netsh.exe'
OriginalFileName:
'netsh.exe'
selection_cli:
CommandLine|contains|all:
-'firewall'
-'delete '
filter_optional_dropbox:
ParentImage|endswith:
'\Dropbox.exe'
CommandLine|contains:
'name=Dropbox'
filter_optional_avast:
ParentImage|endswith:
'\instup.exe'
CommandLine|contains:
'advfirewall firewall delete rule name="Avast Antivirus Admin Client"'
condition:
all of selection_* and not 1 of filter_optional_*
Falsepositives:
-Legitimate administration activity
-Software installations and removal
Level:
medium