Windows: Detect netsh.exe Commands Disabling Firewall
Flags netsh.exe executions that include command-line patterns used to disable Windows firewall.
FreeUnreviewedSigmamediumv1
windows-detect-netsh-exe-commands-disabling-firewall-57c4bf16
title: "Windows: Detect netsh.exe Commands Disabling Firewall"
id: cb8a0a8c-cf6f-4e2c-bd7d-9af6f3a52de5
status: test
description: This rule matches process creation events where netsh.exe is executed with command-line parameters intended to disable Windows firewall functionality. Attackers may impair host defenses by turning off firewall protections to enable persistence, lateral movement, or reduce detection. It relies on telemetry for process creation, including the executable name (netsh.exe) and command-line content containing specific firewall-related tokens.
references:
- https://www.winhelponline.com/blog/enable-and-disable-windows-firewall-quickly-using-command-line/
- https://app.any.run/tasks/210244b9-0b6b-4a2c-83a3-04bd3175d017/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.004/T1562.004.md#atomic-test-1---disable-microsoft-defender-firewall
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_netsh_fw_disable.yml
author: Fatih Sirin, Huntrule Team
date: 2019-11-01
modified: 2023-02-13
tags:
- attack.defense-impairment
- attack.t1686.003
- attack.s0108
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \netsh.exe
- OriginalFileName: netsh.exe
selection_cli_1:
CommandLine|contains|all:
- firewall
- set
- opmode
- disable
selection_cli_2:
CommandLine|contains|all:
- advfirewall
- set
- state
- off
condition: selection_img and 1 of selection_cli_*
falsepositives:
- Legitimate administration activity
level: medium
license: DRL-1.1
related:
- id: 57c4bf16-227f-4394-8ec7-1b745ee061c3
type: derived
What it detects
This rule matches process creation events where netsh.exe is executed with command-line parameters intended to disable Windows firewall functionality. Attackers may impair host defenses by turning off firewall protections to enable persistence, lateral movement, or reduce detection. It relies on telemetry for process creation, including the executable name (netsh.exe) and command-line content containing specific firewall-related tokens.
Known false positives
- Legitimate administration activity
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.