Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)
Alerts on Windows Firewall exception rule additions (Event IDs 2004/2071/2097), excluding common benign paths.
- Product
- windows
- Service
- firewall-as
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2022-02-19
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Windows systems where a new Windows Defender Firewall exception list rule is added, using firewall-as events with Event IDs 2004, 2071, and 2097. Adding firewall exceptions can allow traffic that would otherwise be blocked, which is useful for attackers attempting to bypass network controls. It relies on Windows firewall auditing telemetry that records rule addition activity and associated application path and modifier process fields.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)"
id: c224d69c-eaeb-45b3-b75b-c8615913c8c1
status: test
description: This rule identifies Windows systems where a new Windows Defender Firewall exception list rule is added, using firewall-as events with Event IDs 2004, 2071, and 2097. Adding firewall exceptions can allow traffic that would otherwise be blocked, which is useful for attackers attempting to bypass network controls. It relies on Windows firewall auditing telemetry that records rule addition activity and associated application path and modifier process fields.
references:
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/dd364427(v=ws.10)
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/firewall_as/win_firewall_as_add_rule.yml
author: frack113, Huntrule Team
date: 2022-02-19
modified: 2025-10-08
tags:
- attack.defense-impairment
- attack.t1686.003
logsource:
product: windows
service: firewall-as
detection:
selection:
EventID:
- 2004
- 2071
- 2097
filter_main_block:
Action: 2
filter_main_generic:
ApplicationPath|startswith:
- C:\Program Files (x86)\
- C:\Program Files\
- C:\Windows\System32\
- C:\Windows\SysWOW64\
- C:\Windows\WinSxS\
filter_main_covered_paths:
ApplicationPath|contains:
- C:\PerfLogs\
- C:\Temp\
- C:\Tmp\
- C:\Users\Public\
- C:\Windows\Tasks\
- C:\Windows\Temp\
- \AppData\Local\Temp\
filter_main_system_dllhost:
ApplicationPath: System
ModifyingApplication: C:\Windows\System32\dllhost.exe
filter_main_tiworker:
ModifyingApplication|startswith: C:\Windows\WinSxS\
ModifyingApplication|endswith: \TiWorker.exe
filter_main_null:
ApplicationPath: null
filter_optional_no_path:
ModifyingApplication:
- C:\Windows\System32\svchost.exe
- C:\Windows\System32\dllhost.exe
ApplicationPath: ""
filter_optional_msmpeng:
- ModifyingApplication|startswith:
- C:\ProgramData\Microsoft\Windows Defender\Platform\
- C:\Program Files\Windows Defender\
ModifyingApplication|endswith: \MsMpEng.exe
- ApplicationPath|startswith:
- C:\ProgramData\Microsoft\Windows Defender\Platform\
- C:\Program Files\Windows Defender\
ApplicationPath|endswith: \MsMpEng.exe
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
level: medium
license: DRL-1.1
related:
- id: cde0a575-7d3d-4a49-9817-b8004a7bf105
type: derived