Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
Flags PowerShell commands attempting to turn off Windows Firewall profiles using Set-NetFirewallProfile.
FreeUnreviewedSigmamediumv1
windows-powershell-disables-windows-firewall-profiles-via-set-netfirewallprofile-12f6b752
title: Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
id: 9d2f80f1-a222-413e-8f87-a772f0d661c2
related:
- id: 488b44e7-3781-4a71-888d-c95abfacf44d
type: similar
- id: 12f6b752-042d-483e-bf9c-915a6d06ad75
type: derived
status: test
description: This rule identifies PowerShell executions that disable Windows Firewall by running Set-NetFirewallProfile with Enabled set to False for one or more firewall profiles (All/Public/Domain/Private). Attackers often impair endpoint defenses to enable subsequent access or persistence while reducing detection and blocking. The detection relies on Windows process creation telemetry, matching PowerShell binaries and their command-line arguments.
references:
- https://www.elastic.co/guide/en/security/current/windows-firewall-disabled-via-powershell.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_disable_firewall.yml
author: Tim Rauch, Elastic (idea), Huntrule Team
date: 2022-09-14
modified: 2023-02-13
tags:
- attack.defense-impairment
- attack.t1685
logsource:
category: process_creation
product: windows
detection:
selection_name:
- Image|endswith:
- \powershell.exe
- \pwsh.exe
- \powershell_ise.exe
- OriginalFileName:
- PowerShell.EXE
- pwsh.dll
selection_args:
CommandLine|contains|all:
- "Set-NetFirewallProfile "
- " -Enabled "
- " False"
selection_opt:
CommandLine|contains:
- " -All "
- Public
- Domain
- Private
condition: all of selection_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
What it detects
This rule identifies PowerShell executions that disable Windows Firewall by running Set-NetFirewallProfile with Enabled set to False for one or more firewall profiles (All/Public/Domain/Private). Attackers often impair endpoint defenses to enable subsequent access or persistence while reducing detection and blocking. The detection relies on Windows process creation telemetry, matching PowerShell binaries and their command-line arguments.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.