Windows Firewall Exception List Rule Modified (Firewall-as Events 2005/2073)

Flags Windows Defender Firewall exception list changes (Event IDs 2005/2073), indicating potential attacker-driven network access changes.

FreeReviewedSigma · Low · v5
Product
windows
Service
firewall-as
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-02-19
Updated
2026-07-31

What it detects

This rule identifies modification of Windows Defender Firewall exception list entries, based on firewall-as events with EventID 2005 (Windows 10) and 2073 (Windows 11). Attackers may change firewall exceptions to allow inbound/outbound access while bypassing host network controls. Telemetry relies on Windows firewall-as event logs that record when exception list rules are modified, optionally excluding certain application paths such as Teams, Keybase, Messenger, Opera, and Brave.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.