PowerShell ScriptBlock adds Windows Firewall Allow rule via New-NetFirewallRule
Flags PowerShell ScriptBlock text that invokes New-NetFirewallRule to add an Allow firewall rule.
FreeUnreviewedSigmalowv1
powershell-scriptblock-adds-windows-firewall-allow-rule-via-new-netfirewallrule-8d31dd2e
title: PowerShell ScriptBlock adds Windows Firewall Allow rule via New-NetFirewallRule
id: a826a242-acd5-446b-ae02-37df2072659b
related:
- id: 51483085-0cba-46a8-837e-4416496d6971
type: similar
- id: 8d31dd2e-b582-48ca-826e-dcaa2c1ca264
type: derived
status: test
description: This rule identifies PowerShell ScriptBlock content that calls the New-NetFirewallRule cmdlet to create a firewall rule with an Allow action. Attackers may use firewall rule creation to permit malicious traffic or change host networking protections for subsequent activity. The detection relies on Script Block Logging telemetry capturing the script text and matching cmdlet usage patterns for Allow rules.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.004/T1562.004.md#atomic-test-24---set-a-firewall-rule-using-new-netfirewallrule
- https://malware.news/t/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/72170
- https://cybersecuritynews.com/rhysida-ransomware-attacking-windows/
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/powershell/powershell_script/posh_ps_new_netfirewallrule_allow.yml
author: frack113, Huntrule Team
date: 2024-05-10
tags:
- attack.defense-impairment
- attack.t1686.003
- detection.threat-hunting
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains: New-NetFirewallRule*-Action*Allow
condition: selection
falsepositives:
- Administrator script
level: low
license: DRL-1.1
What it detects
This rule identifies PowerShell ScriptBlock content that calls the New-NetFirewallRule cmdlet to create a firewall rule with an Allow action. Attackers may use firewall rule creation to permit malicious traffic or change host networking protections for subsequent activity. The detection relies on Script Block Logging telemetry capturing the script text and matching cmdlet usage patterns for Allow rules.
Known false positives
- Administrator script
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.