1200KM / detection
T1686.003 Windows Host Firewall — Detection Rules
Detection workspace for T1686.003 Windows Host Firewall: 17 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Uncommon New Firewall Rule Added In Windows Firewall Exception List · test · medium · {"product":"windows","service":"firewall-as"}
- New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application · test · high · {"product":"windows","service":"firewall-as"}
- New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE · test · medium · {"product":"windows","service":"firewall-as"}
- All Rules Have Been Deleted From The Windows Firewall Configuration · test · high · {"product":"windows","service":"firewall-as"}
- A Rule Has Been Deleted From The Windows Firewall Exception List · test · medium · {"product":"windows","service":"firewall-as"}
- The Windows Defender Firewall Service Failed To Load Group Policy · test · low · {"product":"windows","service":"firewall-as"}
- Windows Defender Firewall Has Been Reset To Its Default Configuration · test · low · {"product":"windows","service":"firewall-as"}
- Windows Firewall Settings Have Been Changed · test · low · {"product":"windows","service":"firewall-as"}
- Windows Firewall Profile Disabled · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- New Firewall Rule Added Via Netsh.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE · test · high · {"category":"process_creation","product":"windows"}
- RDP Connection Allowed Via Netsh.EXE · test · high · {"category":"process_creation","product":"windows"}
- Firewall Rule Deleted Via Netsh.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Firewall Disabled via Netsh.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Netsh Allow Group Policy on Microsoft Defender Firewall · test · medium · {"category":"process_creation","product":"windows"}
- Disable Microsoft Defender Firewall via Registry · test · medium · {"category":"registry_set","product":"windows"}
- Disable Windows Firewall by Registry · test · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0901 Detect Windows Firewall
AN2043 Analytic 2043
Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1686.003 simulation workspace
- Network Connection Creation · DC0082
- Process Creation · DC0032
- Service Creation · DC0060
- Windows Registry Key Creation · DC0056
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.