Suspicious Firewall Rule Added to Open RDP Port 3389 via netsh

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects netsh adding an advanced firewall rule that opens local port 3389, the Remote Desktop port, observed in a Huntress analysis of exploited RDP misconfigurations. Attackers create this rule to expose RDP through the host firewall after enabling the service. A command-line firewall change opening 3389 during suspicious activity indicates preparation for remote interactive access.

Related detections9 linkedT1686 — drag to rearrange
Suspicious Remote Desktop Enablement via Registry fDenyTSConnections and Firewall Rule (via process_creation)
Malicious Remote Desktop Enablement via Netsh
Suspicious RDP Enablement via fDenyTSConnections Registry Modification [Huntress] #2
Suspicious SSH Reverse Tunnel Execution via process_creation
Suspicious VMware PCI Device Disabled via Devcon
Suspicious Remote Desktop Enablement via Registry fDenyTSConnections
Possible Firewall Rule Manipulation via netsh advfirewall by FishMonger
Suspicious netsh Firewall Rule Masquerading as SSTP HTTP
Suspicious Disabling of WinRM Service via sc config
Suspicious Firewall Rule Added to Open RDP Port 3389 via netsh
Pivot detection · T1686 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.