Windows Firewall Allow Rule Added via WmiPrvSE.exe

Flags Windows firewall allow-rule additions where WmiPrvSE.exe is the modifying application.

FreeReviewedSigma · Medium · v2
Product
windows
Service
firewall-as
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-05-10
Updated
2026-07-31

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule identifies when a new Windows Defender Firewall exception entry is added with an Allow action and the modifying application is WmiPrvSE.exe. Attackers can use WMI to alter local firewall policy to enable or maintain access while bypassing host-based network restrictions. Telemetry relies on Windows Firewall/Defender firewall logging events that record rule creation (Event IDs 2004/2071/2097), the rule action, and the process path ending in WmiPrvSE.exe.

Related detections9 linkedT1686.003 — drag to rearrange
Windows Firewall Exception Rule Added for Application in Suspicious Path
Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Windows Registry: Disable Firewall via EnableFirewall DWORD Policies
Windows Firewall rule deleted via netsh.exe command line
Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
Windows Defender Firewall Reset to Default Configuration (Firewall-as Service)
Windows Defender Firewall Service Failed to Load Group Policy (Event ID 2009)
Windows Firewall exception rule deleted (Windows Firewall/Defender) EventID 2006/2052
Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)
Windows Firewall Allow Rule Added via WmiPrvSE.exe
Pivot detection · T1686.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.