Windows Registry: Disable Firewall via EnableFirewall DWORD Policies

Flags registry policy changes that set Windows Firewall EnableFirewall to 0 for Domain or Standard profiles.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-08-19
Updated
2026-07-30

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule matches registry set events where the EnableFirewall policy DWORD is written with value 0x00000000 for the StandardProfile or DomainProfile Windows Firewall policies. Disabling firewall protections is a defense-impairment tactic that can make host and network traffic easier to access for an attacker. It relies on telemetry from registry set activity that records the target registry path and the DWORD value written.

Related detections9 linkedT1686.003 — drag to rearrange
Windows Firewall Allow Rule Added via WmiPrvSE.exe
Windows Firewall Exception Rule Added for Application in Suspicious Path
Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Windows Firewall rule deleted via netsh.exe command line
Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
Windows Defender Firewall Reset to Default Configuration (Firewall-as Service)
Windows Defender Firewall Service Failed to Load Group Policy (Event ID 2009)
Windows Firewall exception rule deleted (Windows Firewall/Defender) EventID 2006/2052
Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)
Windows Registry: Disable Firewall via EnableFirewall DWORD Policies
Pivot detection · T1686.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.