Suspicious disablement of the Windows Firewall
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
7 Days
Required Data
XDR Agent
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify System Firewall (T1686)
Severity
Low
Description
The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers.
Attacker's Goals
An attacker may turn the firewall off to exfiltrate data and communicate with C2 servers.
Investigative actions
Check whether the command line executed is benign or normal for the host and/or user performing it.
Investigate the endpoint to determine if the process is legitimately disabling the firewall.
PreviousSuspicious disablement of the Windows Firewall using PowerShell commands
NextSuspicious DKIM Result
Was this helpful?
