Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)

Alerts on Windows Firewall exception rule additions (Event IDs 2004/2071/2097), excluding common benign paths.

FreeReviewedSigma · Medium · v2
Product
windows
Service
firewall-as
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-02-19
Updated
2026-07-31
title: "Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)"
id: c224d69c-eaeb-45b3-b75b-c8615913c8c1
status: test
description: This rule identifies Windows systems where a new Windows Defender Firewall exception list rule is added, using firewall-as events with Event IDs 2004, 2071, and 2097. Adding firewall exceptions can allow traffic that would otherwise be blocked, which is useful for attackers attempting to bypass network controls. It relies on Windows firewall auditing telemetry that records rule addition activity and associated application path and modifier process fields.
references:
  - https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/dd364427(v=ws.10)
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/firewall_as/win_firewall_as_add_rule.yml
author: frack113, Huntrule Team
date: 2022-02-19
modified: 2025-10-08
tags:
  - attack.defense-impairment
  - attack.t1686.003
logsource:
  product: windows
  service: firewall-as
detection:
  selection:
    EventID:
      - 2004
      - 2071
      - 2097
  filter_main_block:
    Action: 2
  filter_main_generic:
    ApplicationPath|startswith:
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\Windows\System32\
      - C:\Windows\SysWOW64\
      - C:\Windows\WinSxS\
  filter_main_covered_paths:
    ApplicationPath|contains:
      - C:\PerfLogs\
      - C:\Temp\
      - C:\Tmp\
      - C:\Users\Public\
      - C:\Windows\Tasks\
      - C:\Windows\Temp\
      - \AppData\Local\Temp\
  filter_main_system_dllhost:
    ApplicationPath: System
    ModifyingApplication: C:\Windows\System32\dllhost.exe
  filter_main_tiworker:
    ModifyingApplication|startswith: C:\Windows\WinSxS\
    ModifyingApplication|endswith: \TiWorker.exe
  filter_main_null:
    ApplicationPath: null
  filter_optional_no_path:
    ModifyingApplication:
      - C:\Windows\System32\svchost.exe
      - C:\Windows\System32\dllhost.exe
    ApplicationPath: ""
  filter_optional_msmpeng:
    - ModifyingApplication|startswith:
        - C:\ProgramData\Microsoft\Windows Defender\Platform\
        - C:\Program Files\Windows Defender\
      ModifyingApplication|endswith: \MsMpEng.exe
    - ApplicationPath|startswith:
        - C:\ProgramData\Microsoft\Windows Defender\Platform\
        - C:\Program Files\Windows Defender\
      ApplicationPath|endswith: \MsMpEng.exe
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
level: medium
license: DRL-1.1
related:
  - id: cde0a575-7d3d-4a49-9817-b8004a7bf105
    type: derived