PowerShell ScriptBlock adds Windows Firewall Allow rule via New-NetFirewallRule

Flags PowerShell ScriptBlock text that invokes New-NetFirewallRule to add an Allow firewall rule.

FreeUnreviewedSigmalowv1
title: PowerShell ScriptBlock adds Windows Firewall Allow rule via New-NetFirewallRule
id: a826a242-acd5-446b-ae02-37df2072659b
related:
  - id: 51483085-0cba-46a8-837e-4416496d6971
    type: similar
  - id: 8d31dd2e-b582-48ca-826e-dcaa2c1ca264
    type: derived
status: test
description: This rule identifies PowerShell ScriptBlock content that calls the New-NetFirewallRule cmdlet to create a firewall rule with an Allow action. Attackers may use firewall rule creation to permit malicious traffic or change host networking protections for subsequent activity. The detection relies on Script Block Logging telemetry capturing the script text and matching cmdlet usage patterns for Allow rules.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.004/T1562.004.md#atomic-test-24---set-a-firewall-rule-using-new-netfirewallrule
  - https://malware.news/t/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/72170
  - https://cybersecuritynews.com/rhysida-ransomware-attacking-windows/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/powershell/powershell_script/posh_ps_new_netfirewallrule_allow.yml
author: frack113, Huntrule Team
date: 2024-05-10
tags:
  - attack.defense-impairment
  - attack.t1686.003
  - detection.threat-hunting
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection:
    ScriptBlockText|contains: New-NetFirewallRule*-Action*Allow
  condition: selection
falsepositives:
  - Administrator script
level: low
license: DRL-1.1

What it detects

This rule identifies PowerShell ScriptBlock content that calls the New-NetFirewallRule cmdlet to create a firewall rule with an Allow action. Attackers may use firewall rule creation to permit malicious traffic or change host networking protections for subsequent activity. The detection relies on Script Block Logging telemetry capturing the script text and matching cmdlet usage patterns for Allow rules.

Known false positives

  • Administrator script

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.