Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0901 — Detect Windows Firewall
DET0901

Detect Windows Firewall

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN2043 Analytic 2043
Windows

Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration.

WinEventLog:Sysmon EventCode=1 WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=12 WinEventLog:System EventCode=7036 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Security EventCode=5156, 5157
[AuthorizedAdminAccounts] Known administrators allowed to manage host firewall settings
[MaintenanceWindow] Approved change windows where firewall modifications are expected
[ExposureCorrelationWindow] Time window to correlate firewall change with new connections/listeners
[SensitivePorts] Ports of concern such as RDP, SMB, WinRM, SSH, custom admin ports
[AllowedManagementParents] Expected parent processes such as SCCM, Intune agent, GPO client
[RuleScopeThreshold] Detect widening from subnet/local scope to Any/0.0.0.0/0

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0901
STIX ID
x-mitre-detection-strategy--488ef272-b2fa-4501-ab6e-97e3ac01816c
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.