Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
Alert on Windows Firewall/Defender firewall setting changes using Events 2002, 2003, 2008, 2082, and 2083.
- Product
- windows
- Service
- firewall-as
- Author
- frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-02-19
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags system activity indicating that Windows Firewall or Windows Defender Firewall settings have been changed. Attackers may modify firewall rules or group policy-applied settings to impair host defenses or enable undesired network access. It relies on Windows firewall-as event telemetry covering event IDs for firewall setting changes, including profile-specific updates and Windows 11 variants.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
id: 1466246a-1ea9-464a-895b-5f9045587c94
status: test
description: This rule flags system activity indicating that Windows Firewall or Windows Defender Firewall settings have been changed. Attackers may modify firewall rules or group policy-applied settings to impair host defenses or enable undesired network access. It relies on Windows firewall-as event telemetry covering event IDs for firewall setting changes, including profile-specific updates and Windows 11 variants.
references:
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/dd364427(v=ws.10)
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/firewall_as/win_firewall_as_setting_change.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-02-19
modified: 2023-04-21
tags:
- attack.defense-impairment
- attack.t1686.003
logsource:
product: windows
service: firewall-as
detection:
selection:
EventID:
- 2002
- 2083
- 2003
- 2082
- 2008
condition: selection
level: low
license: DRL-1.1
related:
- id: 00bb5bd5-1379-4fcf-a965-a5b6f7478064
type: derived