<<< Hide Navigation Hide TOC >>>
Firewall Rule Deleted Via Netsh.EXE (1a5fefe6-734f-452e-a07d-fc1c35bce4b2)
Detects the removal of a port or application rule in the Windows Firewall configuration using netsh
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Disable or Modify System Firewall - T1562.004 (5372c5fe-f424-4def-bcd5-d3a8e770f07b) | Attack Pattern | Firewall Rule Deleted Via Netsh.EXE (1a5fefe6-734f-452e-a07d-fc1c35bce4b2) | Sigma-Rules | 1 |
Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) | Attack Pattern | Disable or Modify System Firewall - T1562.004 (5372c5fe-f424-4def-bcd5-d3a8e770f07b) | Attack Pattern | 2 |