PowerShell New-NetFirewallRule Adds Windows Allow Firewall Rule

Alert on PowerShell creating a new Windows firewall rule that sets the action to Allow via New-NetFirewallRule.

FreeUnreviewedSigmalowv1
title: PowerShell New-NetFirewallRule Adds Windows Allow Firewall Rule
id: a0839538-beb7-4617-8f90-105e72ac367b
related:
  - id: 8d31dd2e-b582-48ca-826e-dcaa2c1ca264
    type: similar
  - id: 51483085-0cba-46a8-837e-4416496d6971
    type: derived
status: test
description: This rule flags process executions where PowerShell (powershell.exe/pwsh.exe/powershell_ise.exe) runs the New-NetFirewallRule cmdlet to create a new firewall rule with an Allow action. Attackers and administrators can use this to modify host network filtering to permit unwanted inbound or outbound traffic. The detection relies on process creation telemetry and matches PowerShell process paths plus command-line content for New-NetFirewallRule, the -Action parameter, and allow.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.004/T1562.004.md#atomic-test-24---set-a-firewall-rule-using-new-netfirewallrule
  - https://malware.news/t/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/72170
  - https://cybersecuritynews.com/rhysida-ransomware-attacking-windows/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_powershell_new_netfirewallrule_allow.yml
author: frack113, Huntrule Team
date: 2024-05-03
tags:
  - attack.defense-impairment
  - attack.t1686.003
  - detection.threat-hunting
logsource:
  category: process_creation
  product: windows
detection:
  selection_name:
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
        - \powershell_ise.exe
    - OriginalFileName:
        - PowerShell.EXE
        - pwsh.dll
  selection_args:
    CommandLine|contains|all:
      - "New-NetFirewallRule "
      - " -Action "
      - allow
  condition: all of selection_*
falsepositives:
  - Administrator script
level: low
license: DRL-1.1

What it detects

This rule flags process executions where PowerShell (powershell.exe/pwsh.exe/powershell_ise.exe) runs the New-NetFirewallRule cmdlet to create a new firewall rule with an Allow action. Attackers and administrators can use this to modify host network filtering to permit unwanted inbound or outbound traffic. The detection relies on process creation telemetry and matches PowerShell process paths plus command-line content for New-NetFirewallRule, the -Action parameter, and allow.

Known false positives

  • Administrator script

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.