Firewall Event ID 2005: Rule modified
- Event ID
- 2005
- Channel
- Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
- Provider
- Microsoft-Windows-Windows Firewall With Advanced Security
- Log file
- Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 2005 means
Event 2005 is written to the Windows Firewall operational log when an existing rule is changed — enabled, disabled, or edited. It carries the complete new definition of the rule (program, ports, addresses, Direction, Action, Active) plus ModifyingUser (SID) and ModifyingApplication (process path).
The event does not include the previous values. To see what changed, compare with an earlier 2004 or 2005 for the same RuleId, or with the rule's state on a known-good host.
Enabling a predefined rule (Remote Desktop, WinRM, File and Printer Sharing, Remote Event Log Management) is a quiet way to open a host for remote access, and it appears here with Active set to 1 rather than as a new rule.
When it is logged
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall channel, enabled by default. No audit policy needed.
Newer Windows 10 and Windows 11 builds log rule modifications under a different event ID in the same channel; if 2005 is absent on a recent build, look for other rule-change events there.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| RuleId | Unique ID of the modified rule; use it to find the rule's earlier events. | ||||||
| RuleName | Display name of the rule. | ||||||
| ApplicationPath | Program the rule applies to, if any. | ||||||
| ServiceName | Service the rule applies to, if any. | ||||||
| Direction | Traffic direction.
| ||||||
| Protocol | IANA protocol number (6 TCP, 17 UDP). | ||||||
| LocalPorts | Local ports covered by the rule after the change. | ||||||
| RemoteAddresses | Remote address scope after the change; watch for scopes widened to any. | ||||||
| Action | Rule action after the change.
| ||||||
| Active | Whether the rule is enabled after the change.
| ||||||
| ModifyingUser | SID of the account that modified the rule. | ||||||
| ModifyingApplication | Full path of the process that modified the rule. |
Common benign sources
- Windows servicing and application updates refreshing their rules.
- Administrators enabling built-in rule groups for a new role or feature.
- Network and management agents adjusting rules they own.
What attackers do that produces it
- Enabling the built-in Remote Desktop or WinRM rules with
netsh advfirewall firewall set rule group=... new enable=yesorEnable-NetFirewallRule. - Switching a block rule to allow, or broadening its remote address scope, to let a tool communicate.
Investigation tips
- Compare the new state with the previous 2004/2005 for the same
RuleIdto identify the actual change. - Resolve
ModifyingUserand correlateModifyingApplicationwith process creation (4688, Sysmon 1) at the same time. - When an inbound remote-access rule was enabled, look for logons that followed (4624 LogonType 3 or 10, RDP 1149).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1686.003 Disable or Modify System Firewall: Windows Host Firewall | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.