All Rules Have Been Deleted From The Windows Firewall Configuration

 Original Source: [Sigma source]
Title: All Rules Have Been Deleted From The Windows Firewall Configuration
Status: test
Description:Detects when a all the rules have been deleted from the Windows Defender Firewall configuration
References:
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/dd364427(v=ws.10)
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2023-01-17
modified:2024-01-22
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686.003'
Logsource:
  • product: windows
  • service: firewall-as
Detection:
  selection:
    EventID:
      -'2033'
      -'2059'

  filter_main_svchost:
    ModifyingApplication|endswith: ':\Windows\System32\svchost.exe'
  filter_optional_msmpeng:
    ModifyingApplication|contains|all:
      -':\ProgramData\Microsoft\Windows Defender\Platform\'
      -'\MsMpEng.exe'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
Level: high